A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access to the root filesystem. The vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending requests with malformed parameters to the system using the console, Secure Shell (SSH), or web API. A successful exploit could allow the attacker to modify the device configuration or cause a DoS.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2020-06-18T02:16:26.888303Z
Updated: 2024-11-15T17:07:03.551Z
Reserved: 2019-12-12T00:00:00
Link: CVE-2020-3336
Vulnrichment
Updated: 2024-08-04T07:30:58.018Z
NVD
Status : Modified
Published: 2020-06-18T03:15:13.667
Modified: 2024-11-21T05:30:49.650
Link: CVE-2020-3336
Redhat
No data.