A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information. Note: This vulnerability only affects Cisco Webex Desk Hub. There are no workarounds that address this vulnerability.
History

Wed, 30 Jul 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco roomos
Cisco telepresence Collaboration Endpoint
CPEs cpe:2.3:a:cisco:telepresence_collaboration_endpoint:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:roomos:-:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco roomos
Cisco telepresence Collaboration Endpoint

Fri, 15 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information. Note: This vulnerability only affects Cisco Webex Desk Hub. There are no workarounds that address this vulnerability.
Title Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2024-11-15T15:08:04.290Z

Updated: 2024-11-15T15:43:30.207Z

Reserved: 2022-10-27T18:47:50.336Z

Link: CVE-2023-20094

cve-icon Vulnrichment

Updated: 2024-11-15T15:43:13.460Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-15T16:15:26.390

Modified: 2025-07-30T17:19:36.683

Link: CVE-2023-20094

cve-icon Redhat

No data.