Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-34758— Cisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service Vulnerability

CVSS 4.4 · Medium EPSS 0.11% · P28
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-34758

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient access controls to a shared memory resource. An attacker could exploit this vulnerability by corrupting a shared memory segment on an affected device. A successful exploit could allow the attacker to cause the device to reload. The device will recover from the corruption upon reboot.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
关键资源的不正确权限授予
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco RoomOS Software和Cisco TelePresence Collaboration Endpoint Software 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco RoomOS Software和Cisco TelePresence Collaboration Endpoint Software都是美国思科(Cisco)公司的产品。Cisco RoomOS Software是一套用于Cisco设备的自动管理软件。该软件主要用于升级、管理Cisco设备的主板固件。Cisco TelePresence Collaboration Endpoint Software是一套协作终端软件。 Cisco RoomOS Software和Cisco TelePrese
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoCisco RoomOS Software n/a -

II. Public POCs for CVE-2021-34758

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-34758

登录查看更多情报信息。

Same Patch Batch · Cisco · 2021-10-06 · 23 CVEs total

CVE-2021-347108.8 HIGHCisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
CVE-2021-347358.8 HIGHCisco ATA 190 Series Analog Telephone Adapter Software Vulnerabilities
CVE-2021-347488.8 HIGHCisco Intersight Virtual Appliance Command Injection Vulnerability
CVE-2021-346988.6 HIGHCisco Web Security Appliance Proxy Service Denial of Service Vulnerability
CVE-2021-15947.5 HIGHCisco Identity Services Engine Privilege Escalation Vulnerability
CVE-2021-347887.0 HIGHCisco AnyConnect Secure Mobility Client for Linux and Mac OS with VPN Posture (HostScan) M
CVE-2021-347066.4 MEDIUMCisco Identity Services Engine XML External Entity Injection Vulnerability
CVE-2021-347426.1 MEDIUMCisco Vision Dynamic Signage Director Reflected Cross-Site Scripting Vulnerability
CVE-2021-15345.8 MEDIUMCisco Email Security Appliance URL Filtering Bypass Vulnerability
CVE-2021-347115.5 MEDIUMCisco IP Phone Software Arbitrary File Read Vulnerability
CVE-2021-347665.4 MEDIUMCisco Smart Software Manager Privilege Escalation Vulnerability
CVE-2021-347444.9 MEDIUMCisco Business 220 Series Smart Switches Static Key and Password Vulnerabilities
CVE-2021-347574.9 MEDIUMCisco Business 220 Series Smart Switches Static Key and Password Vulnerabilities
CVE-2021-347724.7 MEDIUMCisco Orbital Open Redirect Vulnerability
CVE-2021-347754.3 MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol Vulnerabiliti
CVE-2021-347764.3 MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol Vulnerabiliti
CVE-2021-347774.3 MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol Vulnerabiliti
CVE-2021-347784.3 MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol Vulnerabiliti
CVE-2021-347794.3 MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol Vulnerabiliti
CVE-2021-347804.3 MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol Vulnerabiliti

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-34758

No comments yet


Leave a comment