Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
TL;DR 📌
A medium-severity information disclosure vulnerability has been identified in Cisco TelePresence Collaboration Endpoint and RoomOS Software. An authenticated attacker could exploit this vulnerability to view sensitive information in clear text. Cisco has released fixed software, and there are no workarounds available.
What happened 🕵️♂️
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software allows an authenticated, remote attacker to view sensitive information in clear text on affected systems. This issue arises when SIP media component logging is enabled, which can lead to the exposure of unencrypted credentials stored in audit logs. An attacker with valid administrative credentials could exploit this vulnerability to access confidential information, potentially including personally identifiable information (PII).
Affected products 🖥️
The following products are affected if they are running a vulnerable release with SIP media component logging enabled:
- Cisco TelePresence CE
- Cisco RoomOS in on-premises operation
- Cisco RoomOS in cloud-aware on-premises operation
Note: Logging is disabled by default and must be explicitly configured.
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 9 | Migrate to a fixed release. | |
| 10 | Migrate to a fixed release. | |
| 11 | 11.32.2.1 | |
| 1.0 | Initial public release. | |
| Cisco TelePresence CE and RoomOS | 11.32.2.1 | |
| Cisco RoomOS | RoomOS July 2025 |
Workarounds 🧯
There are no workarounds that address this vulnerability.
Risk in context 🎯
The vulnerability has a CVSS score of 4.9, indicating a medium level of risk. While it requires valid administrative credentials for exploitation, the potential exposure of sensitive information, including PII, poses a significant concern for organizations using affected Cisco products.
Fast facts ⚡
- Vulnerability: Information disclosure in logging component
- CVSS Score: 4.9 (Medium)
- Exploitation: Requires valid administrative credentials
- Workarounds: None available
- Fixed Software: Available for various versions
For leadership 🧭
Executive summary. Video conferencing endpoints running RoomOS or TelePresence CE with SIP media component logging enabled may store credentials and other sensitive data unencrypted in audit logs, readable by anyone with admin access. There’s no workaround, so it should be scheduled for patching at the next available window rather than treated as an emergency.
Why it matters:
- Enabling SIP media component logging on RoomOS or TelePresence CE causes credentials and potentially PII to be written to audit logs in clear text rather than masked or encrypted.
- Any account with valid administrative credentials on the endpoint can read these logs, turning a routine diagnostic feature into a route to harvest further credentials.
- No workaround exists, so exposure persists on any vulnerable, logging-enabled device until the fixed software is installed.
- Affects on-premises and cloud-aware on-premises RoomOS deployments as well as TelePresence CE, making this relevant to most meeting-room endpoint fleets.
Now / Next / Later:
- Now: Check whether SIP media component logging is enabled on any Cisco TelePresence CE or RoomOS endpoints and, if it’s not needed for active troubleshooting, disable it to stop further clear-text credential capture.
- Next: Upgrade affected endpoints to the first fixed release for their train — 11.32.2.1 for TelePresence CE and RoomOS, or RoomOS July 2025 — and migrate any devices still on release 9 or 10 to a supported, fixed train.
- Later: Restrict which admin accounts can enable diagnostic logging on collaboration endpoints and review audit log content periodically to catch sensitive data exposure before it accumulates.