A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the xAPI of the affected software. An attacker could exploit this vulnerability by sending a crafted request to the xAPI. A successful exploit could allow the attacker to read and write arbitrary files in the system. To exploit this vulnerability, an attacker would need either an In-Room Control or administrator account.

Project Subscriptions

Vendors Products
Ex60 Firmware Subscribe
Ex90 Firmware Subscribe
Sx10 Firmware Subscribe
Sx20 Firmware Subscribe
Sx80 Firmware Subscribe
Telepresence Codec C40 Subscribe
Telepresence Codec C40 Firmware Subscribe
Telepresence Codec C60 Subscribe
Telepresence Codec C60 Firmware Subscribe
Telepresence Codec C90 Subscribe
Telepresence Codec C90 Firmware Subscribe
Telepresence Mx200 Subscribe
Telepresence Mx200 Firmware Subscribe
Telepresence Mx300 Subscribe
Telepresence Mx300 Firmware Subscribe
Telepresence Mx700 Subscribe
Telepresence Mx700 Firmware Subscribe
Telepresence Mx800 Subscribe
Telepresence Mx800 Firmware Subscribe
Webex Board 55 Subscribe
Webex Board 55 Firmware Subscribe
Webex Board 55s Subscribe
Webex Board 55s Firmware Subscribe
Webex Board 70 Subscribe
Webex Board 70 Firmware Subscribe
Webex Board 70s Subscribe
Webex Board 70s Firmware Subscribe
Webex Board 85s Subscribe
Webex Board 85s Firmware Subscribe
Webex Dx70 Subscribe
Webex Dx70 Firmware Subscribe
Webex Dx80 Subscribe
Webex Dx80 Firmware Subscribe
Webex Room 55 Subscribe
Webex Room 55 Firmware Subscribe
Webex Room 70 Subscribe
Webex Room 70 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-24414 A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the xAPI of the affected software. An attacker could exploit this vulnerability by sending a crafted request to the xAPI. A successful exploit could allow the attacker to read and write arbitrary files in the system. To exploit this vulnerability, an attacker would need either an In-Room Control or administrator account.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 13 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-13T18:06:58.585Z

Reserved: 2019-12-12T00:00:00

Link: CVE-2020-3143

cve-icon Vulnrichment

Updated: 2024-08-04T07:24:00.620Z

cve-icon NVD

Status : Modified

Published: 2020-09-23T01:15:15.410

Modified: 2024-11-21T05:30:24.860

Link: CVE-2020-3143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses