{"id":"CVE-2022-20793","title":"Cisco Touch 10 Device Insufficient Identity Verification Vulnerability","summary":"A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device.\r\n\r\nThi…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","cvssSource":"vendor","vendor":"Cisco","product":"Cisco TelePresence Endpoint Software (TC/CE)","affected":["telepresence_endpoint_software_tc_ce","roomos_software"],"published":"2022-10-05","updated":"2022-10-05","sourceUpdated":"2022-10-05T16:00:00+00:00","source":"CSAF","sourceUrl":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CTT-IVV-4A66Dsfj","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CTT-IVV-4A66Dsfj"},{"url":"https://software.cisco.com"}],"tags":["csaf","vendor-advisory","cisco"],"epss":0.00425,"epssPercentile":0.34011,"ingestedAt":"2026-09-08T15:58:18.537Z","slug":"CVE-2022-20793","body":"## Overview\n\nA vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device.\r\n\r\nThis vulnerability is due to insufficient identity verification. An attacker could exploit this vulnerability by impersonating a legitimate device and responding to the pairing broadcast from an affected device. A successful exploit could allow the attacker to access the affected device while impersonating a legitimate device.\r\n\r\nThere are no workarounds that address this vulnerability.\n\n## Vendor advisories\n\n- **cisco-sa-CTT-IVV-4A66Dsfj** · Cisco · affected: Cisco TelePresence Endpoint Software (TC/CE), Cisco RoomOS Software · updated 2022-10-05 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-CTT-IVV-4A66Dsfj)\n\n**Cisco Touch 10 Devices Insufficient Identity Verification Vulnerability**. Released 2022-10-05.\n\nAffected:\n\n- Cisco TelePresence Endpoint Software (TC/CE)\n- Cisco RoomOS Software\n\n## Remediation\n\nCisco has released software updates that address this vulnerability. https://software.cisco.com","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}