---
id: CVE-2023-20002
title: >-
  Cisco TelePresence CE and RoomOS Software Server-Side Request Forgery
  Vulnerability
summary: >-
  Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE)
  Software and Cisco RoomOS Software could allow an authenticated, local
  attacker to conduct server-side request forgery (SSRF) attacks through an
  affected device or …
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cvssSource: vendor
vendor: Cisco
product: Cisco TelePresence Endpoint Software (TC/CE)
affected:
  - telepresence_endpoint_software_tc_ce
  - roomos_software
published: '2023-01-11'
updated: '2023-03-07'
sourceUpdated: '2023-03-07T14:21:36+00:00'
source: CSAF
sourceUrl: >-
  https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK
  - url: 'https://software.cisco.com'
tags:
  - csaf
  - vendor-advisory
  - cisco
epss: 0.00161
epssPercentile: 0.05696
ingestedAt: '2026-09-08T15:58:18.538Z'
---

## Overview

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device.

For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

## Vendor advisories

- **cisco-sa-roomos-dkjGFgRK** · Cisco · affected: Cisco TelePresence Endpoint Software (TC/CE), Cisco RoomOS Software · updated 2023-03-07 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK)

**Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities**. Released 2023-01-11, updated 2023-03-07.

Affected:

- Cisco TelePresence Endpoint Software (TC/CE)
- Cisco RoomOS Software

## Remediation

Cisco has released software updates that address this vulnerability. https://software.cisco.com
