漏洞信息
# 思科协作终端RoomOS信息泄露漏洞
## 概述
Cisco TelePresence Collaboration Endpoint (CE) 和 Cisco RoomOS Software 的日志组件存在漏洞,允许经过身份验证的远程攻击者以明文形式查看敏感信息。
## 影响版本
未明确指出具体影响版本,需参考官方公告或软件更新日志确认版本范围。
## 漏洞细节
当启用 SIP 媒体组件日志功能时,部分凭证未加密存储在系统日志中。攻击者若拥有有效的管理员凭证,即可访问审计日志并从中获取其本无权限访问的凭证信息。
## 影响
攻击者可通过这些明文凭证访问系统中的敏感数据,其中可能包含个人身份信息(PII),从而导致信息泄露与进一步的未授权访问。
提示
尽管我们采用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。
神龙会尽力确保数据准确,但也请结合实际情况进行甄别与判断。
神龙祝您一切顺利!
漏洞标题
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
漏洞描述信息
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability exists because certain unencrypted credentials are stored when SIP media component logging is enabled. An attacker could exploit this vulnerability by accessing the audit logs on an affected system and obtaining credentials to which they may not normally have access. A successful exploit could allow the attacker to use those credentials to access confidential information, some of which may contain personally identifiable information (PII).
Note: To access the logs that are stored in the Webex Cloud or stored on the device itself, an attacker must have valid administrative credentials.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
漏洞类别
通过日志文件的信息暴露
漏洞标题
Cisco TelePresence Collaboration Endpoint Software 日志信息泄露漏洞
漏洞描述信息
Cisco TelePresence Collaboration Endpoint Software是美国思科(Cisco)公司的一套协作终端软件。 Cisco TelePresence Collaboration Endpoint Software存在日志信息泄露漏洞,该漏洞源于启用SIP媒体组件日志记录时会存储未加密凭据,可能导致敏感信息泄露。
CVSS信息
N/A
漏洞类别
日志信息泄露