CVE-2022-20794

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
04/05/2022
Last modified:
07/11/2023

Description

Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an attacker-controlled destination. For more information about these vulnerabilities, see the Details section of this advisory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:telepresence_collaboration_endpoint:*:*:*:*:*:*:*:* 9.15.0.11 (excluding)
cpe:2.3:a:cisco:telepresence_collaboration_endpoint:*:*:*:*:*:*:*:* 10.0.0.0 (including) 10.8.2.5 (excluding)
cpe:2.3:o:cisco:roomos:*:*:*:*:*:*:*:* 2021-05 (excluding)