Lucene search

K
ciscoCiscoCISCO-SA-TPCE-RMOS-MEM-DOS-RCK56TT
HistoryOct 06, 2021 - 4:00 p.m.

Cisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service Vulnerability

2021-10-0616:00:00
tools.cisco.com
23
cisco
telepresence
roomos
dos
vulnerability
memory management
access controls
software updates

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

EPSS

0

Percentile

5.1%

It was previously published that a vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition.

This vulnerability is due to insufficient access controls to a shared memory resource. An attacker could exploit this vulnerability by corrupting a shared memory segment on an affected device. A successful exploit could allow the attacker to cause the device to reload. The device will recover from the corruption upon reboot.

After additional investigation it was determined that this vulnerability is not exploitable in production software. Cisco has provided software updates for this issue.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tpce-rmos-mem-dos-rck56tT [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tpce-rmos-mem-dos-rck56tT”]

Affected configurations

Vulners
Node
ciscotelepresence_ce_softwareMatchany
OR
ciscotelepresence_ce_softwareMatchany
VendorProductVersionCPE
ciscotelepresence_ce_softwareanycpe:2.3:a:cisco:telepresence_ce_software:any:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

EPSS

0

Percentile

5.1%

Related for CISCO-SA-TPCE-RMOS-MEM-DOS-RCK56TT