VULNERABILITY

Cisco TelePresence Endpoint Software (TC/CE): CVE-2022-20768: Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability

Try Surface Command Get a continuous 360° view of your attack surface
Back to Search

Cisco TelePresence Endpoint Software (TC/CE): CVE-2022-20768: Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability

Severity
6
CVSS
(AV:N/AC:L/Au:M/C:C/I:N/A:N)
Published
07/06/2022
Created
10/05/2024
Added
09/30/2024
Modified
02/14/2025

Description

A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to access confidential information, some of which may contain personally identifiable information (PII). Note: To access the logs that are stored in the RoomOS Cloud, an attacker would need valid Administrator-level credentials.

Solution(s)

  • cisco-telepresence-ce-upgrade-latest

insightVM

Advanced vulnerability management analytics and reporting.
Key Features
  • Lightweight Endpoint Agent
  • Live Dashboards
  • Real Risk Prioritization
  • IT-Integrated Remediation Projects
  • Cloud, Virtual, and Container Assessment
  • Integrated Threat Feeds
  • Easy-to-Use RESTful API
  • Automation-Assisted Patching
  • Automated Containment
Free InsightVM Trial View All Features

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;