CVE-2023-20094
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Nov 15, 2024
CWE ID 125
Summary
CVE-2023-20094 is a vulnerability affecting Cisco TelePresence CE and RoomOS. An unauthenticated, adjacent attacker can exploit this issue by sending a crafted request to an affected device, leading to an out-of-bounds read that discloses sensitive information. The root cause is the software's improper bounds checks. Notably, this vulnerability targets only Cisco Webex Desk Hub and no known workarounds are available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.