{"id":"CVE-2023-20008","title":"Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability","summary":"Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …","severity":"medium","cvss":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","cvssSource":"vendor","vendor":"Cisco","product":"Cisco RoomOS Software","affected":["roomos_software","telepresence_endpoint_software_tc_ce"],"published":"2023-01-11","updated":"2023-03-07","sourceUpdated":"2023-03-07T14:21:36+00:00","source":"CSAF","sourceUrl":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK"},{"url":"https://software.cisco.com"}],"tags":["csaf","vendor-advisory","cisco"],"epss":0.00194,"epssPercentile":0.09334,"ingestedAt":"2026-09-08T15:58:18.537Z","slug":"CVE-2023-20008","body":"## Overview\n\nMultiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device.\r\n\r\nFor more information about these vulnerabilities, see the Details [\"#details\"] section of this advisory.\r\n\r\nCisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.\n\n## Vendor advisories\n\n- **cisco-sa-roomos-dkjGFgRK** · Cisco · affected: Cisco RoomOS Software, Cisco TelePresence Endpoint Software (TC/CE) · updated 2023-03-07 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK)\n\n**Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities**. Released 2023-01-11, updated 2023-03-07.\n\nAffected:\n\n- Cisco RoomOS Software\n- Cisco TelePresence Endpoint Software (TC/CE)\n\n## Remediation\n\nCisco has released software updates that address this vulnerability. https://software.cisco.com","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":24.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}