A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the xAPI of the affected software. An attacker could exploit this vulnerability by sending a crafted request to the xAPI. A successful exploit could allow the attacker to read and write arbitrary files in the system. To exploit this vulnerability, an attacker would need either an In-Room Control or administrator account.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Ex60
Subscribe
Ex60 Firmware
Subscribe
Ex90
Subscribe
Ex90 Firmware
Subscribe
Sx10
Subscribe
Sx10 Firmware
Subscribe
Sx20
Subscribe
Sx20 Firmware
Subscribe
Sx80
Subscribe
Sx80 Firmware
Subscribe
Telepresence Codec C40
Subscribe
Telepresence Codec C40 Firmware
Subscribe
Telepresence Codec C60
Subscribe
Telepresence Codec C60 Firmware
Subscribe
Telepresence Codec C90
Subscribe
Telepresence Codec C90 Firmware
Subscribe
Telepresence Mx200
Subscribe
Telepresence Mx200 Firmware
Subscribe
Telepresence Mx300
Subscribe
Telepresence Mx300 Firmware
Subscribe
Telepresence Mx700
Subscribe
Telepresence Mx700 Firmware
Subscribe
Telepresence Mx800
Subscribe
Telepresence Mx800 Firmware
Subscribe
Webex Board 55
Subscribe
Webex Board 55 Firmware
Subscribe
Webex Board 55s
Subscribe
Webex Board 55s Firmware
Subscribe
Webex Board 70
Subscribe
Webex Board 70 Firmware
Subscribe
Webex Board 70s
Subscribe
Webex Board 70s Firmware
Subscribe
Webex Board 85s
Subscribe
Webex Board 85s Firmware
Subscribe
Webex Dx70
Subscribe
Webex Dx70 Firmware
Subscribe
Webex Dx80
Subscribe
Webex Dx80 Firmware
Subscribe
Webex Room 55
Subscribe
Webex Room 55 Firmware
Subscribe
Webex Room 70
Subscribe
Webex Room 70 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-24414 | A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the xAPI of the affected software. An attacker could exploit this vulnerability by sending a crafted request to the xAPI. A successful exploit could allow the attacker to read and write arbitrary files in the system. To exploit this vulnerability, an attacker would need either an In-Room Control or administrator account. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 13 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-13T18:06:58.585Z
Reserved: 2019-12-12T00:00:00
Link: CVE-2020-3143
Updated: 2024-08-04T07:24:00.620Z
Status : Modified
Published: 2020-09-23T01:15:15.410
Modified: 2024-11-21T05:30:24.860
Link: CVE-2020-3143
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD