CVE Feed

    Dashboard / CVE / CVE-2020-3143

    CVE-2020-3143

    A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the xAPI of the affected software. An attacker could exploit this vulnerability by sending a crafted request to the xAPI. A successful exploit could allow the attacker to read and write arbitrary files in the system. To exploit this vulnerability, an attacker would need either an In-Room Control or administrator account.

    Published:Sep 23, 2020
    Last Modified:Nov 21, 2024
    EPS:Sep 23, 2020
    EPSS Score:0.02628
    CVSS Score:7.2

    Affected Products

    Vendor
    Cisco
    Product
    Ex60
    Vendor
    Cisco
    Product
    Ex60 Firmware
    Vendor
    Cisco
    Product
    Ex90
    Vendor
    Cisco
    Product
    Ex90 Firmware
    Vendor
    Cisco
    Product
    Sx10
    Vendor
    Cisco
    Product
    Sx10 Firmware
    Vendor
    Cisco
    Product
    Sx20
    Vendor
    Cisco
    Product
    Sx20 Firmware
    Vendor
    Cisco
    Product
    Sx80
    Vendor
    Cisco
    Product
    Sx80 Firmware
    Vendor
    Cisco
    Product
    Telepresence Codec C40
    Vendor
    Cisco
    Product
    Telepresence Codec C40 Firmware
    Vendor
    Cisco
    Product
    Telepresence Codec C60
    Vendor
    Cisco
    Product
    Telepresence Codec C60 Firmware
    Vendor
    Cisco
    Product
    Telepresence Codec C90
    Vendor
    Cisco
    Product
    Telepresence Codec C90 Firmware
    Vendor
    Cisco
    Product
    Telepresence Mx200
    Vendor
    Cisco
    Product
    Telepresence Mx200 Firmware
    Vendor
    Cisco
    Product
    Telepresence Mx300
    Vendor
    Cisco
    Product
    Telepresence Mx300 Firmware
    Vendor
    Cisco
    Product
    Telepresence Mx700
    Vendor
    Cisco
    Product
    Telepresence Mx700 Firmware
    Vendor
    Cisco
    Product
    Telepresence Mx800
    Vendor
    Cisco
    Product
    Telepresence Mx800 Firmware
    Vendor
    Cisco
    Product
    Webex Board 55
    Vendor
    Cisco
    Product
    Webex Board 55 Firmware
    Vendor
    Cisco
    Product
    Webex Board 55s
    Vendor
    Cisco
    Product
    Webex Board 55s Firmware
    Vendor
    Cisco
    Product
    Webex Board 70
    Vendor
    Cisco
    Product
    Webex Board 70 Firmware
    Vendor
    Cisco
    Product
    Webex Board 70s
    Vendor
    Cisco
    Product
    Webex Board 70s Firmware
    Vendor
    Cisco
    Product
    Webex Board 85s
    Vendor
    Cisco
    Product
    Webex Board 85s Firmware
    Vendor
    Cisco
    Product
    Webex Dx70
    Vendor
    Cisco
    Product
    Webex Dx70 Firmware
    Vendor
    Cisco
    Product
    Webex Dx80
    Vendor
    Cisco
    Product
    Webex Dx80 Firmware
    Vendor
    Cisco
    Product
    Webex Room 55
    Vendor
    Cisco
    Product
    Webex Room 55 Firmware
    Vendor
    Cisco
    Product
    Webex Room 70
    Vendor
    Cisco
    Product
    Webex Room 70 Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High