---
id: CVE-2023-20008
title: >-
  Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File
  Write Vulnerability
summary: >-
  Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE)
  Software and Cisco RoomOS Software could allow an authenticated, local
  attacker to conduct server-side request forgery (SSRF) attacks through an
  affected device or …
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'
cvssSource: vendor
vendor: Cisco
product: Cisco RoomOS Software
affected:
  - roomos_software
  - telepresence_endpoint_software_tc_ce
published: '2023-01-11'
updated: '2023-03-07'
sourceUpdated: '2023-03-07T14:21:36+00:00'
source: CSAF
sourceUrl: >-
  https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK
  - url: 'https://software.cisco.com'
tags:
  - csaf
  - vendor-advisory
  - cisco
epss: 0.00194
epssPercentile: 0.09334
ingestedAt: '2026-09-08T15:58:18.537Z'
---

## Overview

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or to overwrite arbitrary files on an affected device.

For more information about these vulnerabilities, see the Details ["#details"] section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

## Vendor advisories

- **cisco-sa-roomos-dkjGFgRK** · Cisco · affected: Cisco RoomOS Software, Cisco TelePresence Endpoint Software (TC/CE) · updated 2023-03-07 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-dkjGFgRK)

**Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities**. Released 2023-01-11, updated 2023-03-07.

Affected:

- Cisco RoomOS Software
- Cisco TelePresence Endpoint Software (TC/CE)

## Remediation

Cisco has released software updates that address this vulnerability. https://software.cisco.com
