CVE-2022-20768Medium· 4.9▾ SunlitA vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnera…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.9%
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.
This vulnerability is due to the storage of certain unencrypted credentials. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials that they may not normally have access to. A successful exploit could allow the attacker to use those credentials to access confidential information, some of which may contain personally identifiable information (PII).
Note: To access the logs that are stored in the RoomOS Cloud, an attacker would need valid Administrator-level credentials.
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability. Released 2022-07-06.
Affected:
Cisco has released software updates that address this vulnerability. https://software.cisco.com
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20119High· 7.5Cisco TelePresence Collaboration Endpoint Software and RoomOS Software Denial of Service Vulnerability (CVE-2026-20119)
CVE-2022-20764Medium· 6.5Cisco RoomsOS Denial of Service Vulnerability
CVE-2022-20776Medium· 5.1Cisco TelePresence Collaboration Endpoint and RoomOS Software Path Traversal Vulnerability
CVE-2022-20955Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
CVE-2023-20004Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
CVE-2023-20008Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability