{"id":"CVE-2021-34758","title":"Cisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service Vulnerability","summary":"It was previously published that a vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment,…","severity":"none","vendor":"Cisco","product":"Cisco TelePresence Endpoint Software (TC/CE)","affected":["telepresence_endpoint_software_tc_ce"],"published":"2021-10-06","updated":"2021-10-15","sourceUpdated":"2021-10-15T21:03:56+00:00","source":"CSAF","sourceUrl":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tpce-rmos-mem-dos-rck56tT","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tpce-rmos-mem-dos-rck56tT"},{"url":"https://software.cisco.com"}],"tags":["csaf","vendor-advisory","cisco"],"epss":0.00186,"epssPercentile":0.08505,"ingestedAt":"2026-09-08T15:58:18.537Z","slug":"CVE-2021-34758","body":"## Overview\n\nIt was previously published that a vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition.\r\n\r\nThis vulnerability is due to insufficient access controls to a shared memory resource. An attacker could exploit this vulnerability by corrupting a shared memory segment on an affected device. A successful exploit could allow the attacker to cause the device to reload. The device will recover from the corruption upon reboot.\r\n\r\nAfter additional investigation it was determined that this vulnerability is not exploitable in production software. Cisco has provided software updates for this issue.\n\n## Vendor advisories\n\n- **cisco-sa-tpce-rmos-mem-dos-rck56tT** · Cisco · affected: Cisco TelePresence Endpoint Software (TC/CE) · updated 2021-10-15 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tpce-rmos-mem-dos-rck56tT)\n\n**Cisco TelePresence Collaboration Endpoint and  RoomOS Software Denial of Service Vulnerability**. Released 2021-10-06, updated 2021-10-15.\n\nAffected:\n\n- Cisco TelePresence Endpoint Software (TC/CE)\n\n## Remediation\n\nCisco has released software updates that address this vulnerability. https://software.cisco.com","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}