{"id":"CVE-2023-20002","title":"Cisco TelePresence CE and RoomOS Software Server-Side Request Forgery Vulnerability","summary":"Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …","severity":"medium","cvss":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cvssSource":"vendor","vendor":"Cisco","product":"Cisco TelePresence Endpoint Software (TC/CE)","affected":["telepresence_endpoint_software_tc_ce","roomos_software"],"published":"2023-01-11","updated":"2023-03-07","sourceUpdated":"2023-03-07T14:21:36+00:00","source":"CSAF","sourceUrl":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK"},{"url":"https://software.cisco.com"}],"tags":["csaf","vendor-advisory","cisco"],"epss":0.00161,"epssPercentile":0.05696,"ingestedAt":"2026-09-08T15:58:18.538Z","slug":"CVE-2023-20002","body":"## Overview\n\nMultiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device.\r\n\r\nFor more information about these vulnerabilities, see the Details [\"#details\"] section of this advisory.\r\n\r\nCisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.\n\n## Vendor advisories\n\n- **cisco-sa-roomos-dkjGFgRK** · Cisco · affected: Cisco TelePresence Endpoint Software (TC/CE), Cisco RoomOS Software · updated 2023-03-07 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK)\n\n**Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities**. Released 2023-01-11, updated 2023-03-07.\n\nAffected:\n\n- Cisco TelePresence Endpoint Software (TC/CE)\n- Cisco RoomOS Software\n\n## Remediation\n\nCisco has released software updates that address this vulnerability. https://software.cisco.com","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":24.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}