← Back

CVE-2022-20793

nvd nist
Published: Nov 15, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitability: 1.6 / Impact: 5.2
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. This vulnerability is due to insufficient identity verification. An attacker could exploit this vulnerability by impersonating a legitimate device and responding to the pairing broadcast from an affected device. A successful exploit could allow the attacker to access the affected device while impersonating a legitimate device.There are no workarounds that address this vulnerability.

Affected (42)

2 products
Roomos
Configuration A
41 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 9.0.1
Version 9.1.1
Version 9.1.2
Version 9.1.3
Version 9.1.4
Version 9.1.5
Version 9.1.6
Version 9.10.1
Version 9.10.2
Version 9.10.3
Version 9.12.3
Version 9.12.4
Version 9.12.5
Version 9.13.0
Version 9.13.1
Version 9.13.2
Version 9.13.3
Version 9.14.3
Version 9.14.4
Version 9.14.5
Version 9.14.6
Version 9.14.7
Version 9.15.0.10
Version 9.15.0.11
Version 9.15.0.13
Version 9.15.0.19
Version 9.15.10.8
Version 9.15.13.0
Version 9.15.3.17
Version 9.15.3.18
Version 9.15.3.19
Version 9.15.3.22
Version 9.15.3.25
Version 9.15.3.26
Version 9.15.8.12
Version 9.2.1
Version 9.2.2
Version 9.2.3
Version 9.2.4
Version 9.9.3
Version 9.9.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

Timeline

No history available yet.