CVE-2022-20793

A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device.
This vulnerability is due to insufficient identity verification. An attacker could exploit this vulnerability by impersonating a legitimate device and responding to the pairing broadcast from an affected device. A successful exploit could allow the attacker to access the affected device while impersonating a legitimate device.There are no workarounds that address this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
ciscoCNA
6.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
ciscotelepresence_collaboration_endpoint
9.0.1
ciscotelepresence_collaboration_endpoint
9.1.1
ciscotelepresence_collaboration_endpoint
9.1.2
ciscotelepresence_collaboration_endpoint
9.1.3
ciscotelepresence_collaboration_endpoint
9.1.4
ciscotelepresence_collaboration_endpoint
9.1.5
ciscotelepresence_collaboration_endpoint
9.1.6
ciscotelepresence_collaboration_endpoint
9.2.1
ciscotelepresence_collaboration_endpoint
9.2.2
ciscotelepresence_collaboration_endpoint
9.2.3
ciscotelepresence_collaboration_endpoint
9.2.4
ciscotelepresence_collaboration_endpoint
9.9.3
ciscotelepresence_collaboration_endpoint
9.9.4
ciscotelepresence_collaboration_endpoint
9.10.1
ciscotelepresence_collaboration_endpoint
9.10.2
ciscotelepresence_collaboration_endpoint
9.10.3
ciscotelepresence_collaboration_endpoint
9.12.3
ciscotelepresence_collaboration_endpoint
9.12.4
ciscotelepresence_collaboration_endpoint
9.12.5
ciscotelepresence_collaboration_endpoint
9.13.0
ciscotelepresence_collaboration_endpoint
9.13.1
ciscotelepresence_collaboration_endpoint
9.13.2
ciscotelepresence_collaboration_endpoint
9.13.3
ciscotelepresence_collaboration_endpoint
9.14.3
ciscotelepresence_collaboration_endpoint
9.14.4
ciscotelepresence_collaboration_endpoint
9.14.5
ciscotelepresence_collaboration_endpoint
9.14.6
ciscotelepresence_collaboration_endpoint
9.14.7
ciscotelepresence_collaboration_endpoint
9.15.0.10
ciscotelepresence_collaboration_endpoint
9.15.0.11
ciscotelepresence_collaboration_endpoint
9.15.0.13
ciscotelepresence_collaboration_endpoint
9.15.0.19
ciscotelepresence_collaboration_endpoint
9.15.3.17
ciscotelepresence_collaboration_endpoint
9.15.3.18
ciscotelepresence_collaboration_endpoint
9.15.3.19
ciscotelepresence_collaboration_endpoint
9.15.3.22
ciscotelepresence_collaboration_endpoint
9.15.3.25
ciscotelepresence_collaboration_endpoint
9.15.3.26
ciscotelepresence_collaboration_endpoint
9.15.8.12
ciscotelepresence_collaboration_endpoint
9.15.10.8
ciscotelepresence_collaboration_endpoint
9.15.13.0
ciscoroomos
-
𝑥
= Vulnerable software versions