CVE-2023-20094 (CNNVD-202411-2060)
中文标题:
Cisco RoomOS Software和Cisco TelePresence Collaboration Endpoint Software 缓冲区错误漏洞
英文标题:
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
漏洞描述
中文描述:
Cisco RoomOS Software和Cisco TelePresence Collaboration Endpoint Software都是美国思科(Cisco)公司的产品。Cisco RoomOS Software是一套用于Cisco设备的自动管理软件。该软件主要用于升级、管理Cisco设备的主板固件。Cisco TelePresence Collaboration Endpoint Software是一套协作终端软件。 Cisco RoomOS Software和Cisco TelePresence Collaboration Endpoint Software存在缓冲区错误漏洞,该漏洞源于受影响的软件执行了不正确的边界检查。未经身份验证的相邻攻击者利用该漏洞能够查看受影响设备上的敏感信息。
英文描述:
A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause an out-of-bounds read that discloses sensitive information. Note: This vulnerability only affects Cisco Webex Desk Hub. There are no workarounds that address this vulnerability.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco RoomOS Software | N/A | - | - |
cpe:2.3:a:cisco:cisco_roomos_software:n_a:*:*:*:*:*:*:*
|
| Cisco | Cisco TelePresence Endpoint Software (TC/CE) | N/A | - | - |
cpe:2.3:a:cisco:cisco_telepresence_endpoint_software_(tc_ce):n_a:*:*:*:*:*:*:*
|
| cisco | telepresence_collaboration_endpoint | - | - | - |
cpe:2.3:a:cisco:telepresence_collaboration_endpoint:-:*:*:*:*:*:*:*
|
| cisco | roomos | - | - | - |
cpe:2.3:o:cisco:roomos:-:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2023-20094 |
2025-11-11 15:21:47 | 2025-11-11 07:38:02 |
| NVD | nvd_CVE-2023-20094 |
2025-11-11 14:59:21 | 2025-11-11 07:46:12 |
| CNNVD | cnnvd_CNNVD-202411-2060 |
2025-11-11 15:11:52 | 2025-11-11 07:59:16 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 缓冲区错误
- cnnvd_id: 未提取 -> CNNVD-202411-2060
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 2 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']