CVE-2023-20090

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Nov 15, 2024
CWE ID 27

Summary

CVE-2023-20090 is a vulnerability affecting Cisco TelePresence CE and RoomOS systems. It grants authenticated, local attackers the ability to elevate privileges to root level on affected devices. The issue arises from inadequate access control on specific CLI commands. An attacker can exploit this flaw by executing a sequence of carefully crafted commands, potentially resulting in privilege escalation. Cisco has issued software updates to mitigate this vulnerability, and currently, no workarounds are available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share