9

CVE-2020-3143

A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software, Cisco TelePresence Codec (TC) Software, and Cisco RoomOS Software could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of user-supplied input to the xAPI of the affected software. An attacker could exploit this vulnerability by sending a crafted request to the xAPI. A successful exploit could allow the attacker to read and write arbitrary files in the system. To exploit this vulnerability, an attacker would need either an In-Room Control or administrator account.

Data is provided by the National Vulnerability Database (NVD)
CiscoEx60 Firmware Version-
   CiscoEx60 Version-
CiscoEx90 Firmware Version-
   CiscoEx90 Version-
CiscoSx10 Firmware Version-
   CiscoSx10 Version-
CiscoSx20 Firmware Version-
   CiscoSx20 Version-
CiscoSx80 Firmware Version-
   CiscoSx80 Version-
CiscoTelepresence Mx200 Firmware Version-
   CiscoTelepresence Mx200 Version-
CiscoTelepresence Mx300 Firmware Version-
   CiscoTelepresence Mx300 Version-
CiscoTelepresence Mx700 Firmware Version-
   CiscoTelepresence Mx700 Version-
CiscoTelepresence Mx800 Firmware Version-
   CiscoTelepresence Mx800 Version-
CiscoWebex Board 55 Firmware Version-
   CiscoWebex Board 55 Version-
CiscoWebex Board 55s Firmware Version-
   CiscoWebex Board 55s Version-
CiscoWebex Board 70 Firmware Version-
   CiscoWebex Board 70 Version-
CiscoWebex Board 70s Firmware Version-
   CiscoWebex Board 70s Version-
CiscoWebex Board 85s Firmware Version-
   CiscoWebex Board 85s Version-
CiscoWebex Dx70 Firmware Version-
   CiscoWebex Dx70 Version-
CiscoWebex Dx80 Firmware Version-
   CiscoWebex Dx80 Version-
CiscoWebex Room 55 Firmware Version-
   CiscoWebex Room 55 Version-
CiscoWebex Room 70 Firmware Version-
   CiscoWebex Room 70 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.28% 0.841
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
psirt@cisco.com 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.