CVE-2022-20793 - CVE House
Back to Database
Status published Medium CVE-2022-20793

Cisco Touch 10 Device Insufficient Identity Verification Vulnerability

Vulnerability Description

A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. This vulnerability is due to insufficient identity verification. An attacker could exploit this vulnerability by impersonating a legitimate device and responding to the pairing broadcast from an affected device. A successful exploit could allow the attacker to access the affected device while impersonating a legitimate device.There are no workarounds that address this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-20793

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco RoomOS Software, Cisco TelePresence Endpoint Software (TC/CE)
Vulnerable Versions:
CE9.10.2, CE9.1.4, CE9.10.3, CE9.1.5, CE9.10.1, CE9.13.0, CE9.1.1, CE9.9.4, CE9.2.1, CE9.1.3, CE9.1.6, CE9.12.3, CE9.13.1, CE9.12.4, CE9.14.3, CE9.14.4, CE9.13.2, CE9.12.5, CE9.14.5, CE9.15.0.10, CE9.15.0.11, CE9.13.3, CE9.15.0.13, CE9.14.6, CE9.15.3.17, CE9.14.7, CE9.15.0.19, CE9.15.3.19, CE9.15.3.18, CE9.0.1, CE9.2.2, CE9.1.2, CE9.9.3, CE9.2.4, CE9.2.3, CE9.15.3.22, CE9.15.8.12, CE9.15.10.8, CE9.15.3.26, CE9.15.3.25, CE9.15.13.0

Timeline

Official Publish: November 15th, 2024
Last Modified: November 15th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.