CVE-2021-34758None▾ SunlitIt was previously published that a vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment,…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
Last analysed / modified upstream
0.2%
It was previously published that a vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition.
This vulnerability is due to insufficient access controls to a shared memory resource. An attacker could exploit this vulnerability by corrupting a shared memory segment on an affected device. A successful exploit could allow the attacker to cause the device to reload. The device will recover from the corruption upon reboot.
After additional investigation it was determined that this vulnerability is not exploitable in production software. Cisco has provided software updates for this issue.
Cisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service Vulnerability. Released 2021-10-06, updated 2021-10-15.
Affected:
Cisco has released software updates that address this vulnerability. https://software.cisco.com
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-1532Medium· 6.5Cisco Telepresence CE and RoomOS Software Arbitrary File Read Vulnerability
CVE-2020-26068Medium· 5.5Cisco Telepresence CE Software and RoomOS Software Unauthorized Configuration Change Vulnerability
CVE-2020-26086Medium· 4.3Cisco TelePresence Collaboration Endpoint Software Information Disclosure Vulnerability (CVE-2020-26086)
CVE-2022-20783High· 7.5Cisco Telepresence CE and RoomOS Software Denial of Service Vulnerability
CVE-2023-20002Medium· 4.4Cisco TelePresence CE and RoomOS Software Server-Side Request Forgery Vulnerability
CVE-2022-20793Medium· 6.8Cisco Touch 10 Device Insufficient Identity Verification Vulnerability