CVE-2022-20793Medium· 6.8▾ SunlitA vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. Thi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device.
This vulnerability is due to insufficient identity verification. An attacker could exploit this vulnerability by impersonating a legitimate device and responding to the pairing broadcast from an affected device. A successful exploit could allow the attacker to access the affected device while impersonating a legitimate device.
There are no workarounds that address this vulnerability.
Cisco Touch 10 Devices Insufficient Identity Verification Vulnerability. Released 2022-10-05.
Affected:
Cisco has released software updates that address this vulnerability. https://software.cisco.com
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-1532Medium· 6.5Cisco Telepresence CE and RoomOS Software Arbitrary File Read Vulnerability
CVE-2020-26068Medium· 5.5Cisco Telepresence CE Software and RoomOS Software Unauthorized Configuration Change Vulnerability
CVE-2020-26086Medium· 4.3Cisco TelePresence Collaboration Endpoint Software Information Disclosure Vulnerability (CVE-2020-26086)
CVE-2022-20783High· 7.5Cisco Telepresence CE and RoomOS Software Denial of Service Vulnerability
CVE-2023-20002Medium· 4.4Cisco TelePresence CE and RoomOS Software Server-Side Request Forgery Vulnerability
CVE-2021-34758NoneCisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service Vulnerability