Lucene search

K
cvelistCiscoCVELIST:CVE-2021-1532
HistoryMay 06, 2021 - 12:51 p.m.

CVE-2021-1532 Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Read Vulnerability

2021-05-0612:51:29
CWE-22
cisco
www.cve.org
4
cisco
telepresence
endpoint
roomos
arbitrary file read
vulnerability
xapi
remote attacker
command validation
filesystem

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

40.6%

A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability is due to insufficient path validation of command arguments. An attacker could exploit this vulnerability by sending a crafted command request to the xAPI. A successful exploit could allow the attacker to read the contents of any file that is located on the device filesystem.

CNA Affected

[
  {
    "product": "Cisco TelePresence Endpoint Software (TC/CE)",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

40.6%

Related for CVELIST:CVE-2021-1532