CVE-2020-3336

HIGH

Cisco TelePresence Collaboration Endpoint Software - DoS

Title source: llm
STIX 2.1

Description

A vulnerability in the software upgrade process of Cisco TelePresence Collaboration Endpoint Software and Cisco RoomOS Software could allow an authenticated, remote attacker to modify the filesystem to cause a denial of service (DoS) or gain privileged access to the root filesystem. The vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by sending requests with malformed parameters to the system using the console, Secure Shell (SSH), or web API. A successful exploit could allow the attacker to modify the device configuration or cause a DoS.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0103
EPSS Percentile 77.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
cisco/roomos
cisco/telepresence_collaboration_endpoint < 9.9.4
Published Jun 18, 2020
Tracked Since Feb 18, 2026