cisco telepresence-collaboration-endpoint CVE-2020-26086 is a vulnerability in Cisco Telepresence Collaboration Endpoint
Published on November 6, 2020

Cisco TelePresence Collaboration Endpoint Software Information Disclosure Vulnerability
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper storage of sensitive information on an affected device. An attacker could exploit this vulnerability by accessing information that should not be accessible to users with low privileges. A successful exploit could allow the attacker to gain access to sensitive information.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2020-26086 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Type

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.


Products Associated with CVE-2020-26086

Want to know whenever a new CVE is published for Cisco Telepresence Collaboration Endpoint? stack.watch will email you.

 

Affected Versions

Cisco TelePresence Endpoint Software (TC/CE) Version n/a is affected by CVE-2020-26086

Exploit Probability

EPSS
0.17%
Percentile
38.63%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.