CVE-2022-20931

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/11/2024
Last modified:
31/07/2025

Description

A vulnerability in the version control of Cisco&amp;nbsp;TelePresence CE Software for Cisco&amp;nbsp;Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device.<br /> This vulnerability is due to insufficient version control. An attacker could exploit this vulnerability by installing an older version of Cisco&amp;nbsp;TelePresence CE Software on an affected device. A successful exploit could allow the attacker to take advantage of vulnerabilities in older versions of the software.Cisco&amp;nbsp;has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:telepresence_collaboration_endpoint:*:*:*:*:*:*:*:* 10.15.2.2 (excluding)