Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability

🚨SEVERITY: MEDIUM — CVSS 4.9Security Advisory

TL;DR 📌

  • A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability exists because certain unencrypted credentials are stored when SIP…
  • Highest CVSS: 4.9 (Medium).
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2025-20329.

What it is

CVE-2025-20329 sits in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software. When logging of the SIP media component is enabled, the affected software writes certain credentials to the audit logs in clear text.

Exploitation requires valid administrative credentials already — this is not an unauthenticated bypass. An authenticated remote attacker with admin access can read the audit logs, either on the device itself or in the Webex Cloud for cloud-aware deployments, and recover credentials they would not otherwise be entitled to use. Those credentials can then be used to reach confidential information, which Cisco notes may include personally identifiable information.

The trigger condition is specific: SIP media component logging must be explicitly turned on. It is disabled by default and is not enabled as part of extended logging, so devices running with default logging configuration are not exposed via this path.

Cisco rates this 4.9 (Medium) under CVSS 3.1, reflecting the high privilege requirement (PR:H) alongside network attack vector and low complexity. There is no indication of public exploitation and it is not listed in CISA’s KEV catalogue.

What to do

  • Check whether SIP media component logging is enabled on any TelePresence CE or RoomOS endpoints (on-premises or cloud-aware). If it isn’t, you’re not exposed to this issue.
  • If logging is enabled, treat any credentials that may already be present in existing audit logs — on-device or in Webex Cloud — as potentially exposed, and rotate them.
  • Upgrade to fixed software: for release 11, move to 11.32.2.1 (on-premises/TelePresence CE) or RoomOS July 2025 (cloud-aware operation). Releases 9 and 10 have no dedicated fix — Cisco’s guidance is to migrate to a fixed release.
  • There is no workaround; disabling SIP media component logging removes the exposure but the only full remediation is the software upgrade.
  • Tighten who holds administrative credentials on these endpoints, since exploitation depends entirely on possessing valid admin access.

For leadership 🧭

Executive summary. This affects Cisco TelePresence CE and RoomOS endpoints only where someone has explicitly turned on SIP media component logging, and it requires the attacker already hold valid admin credentials, so it is not an open door but a privilege-escalation risk within your own admin population. Confirm logging status and rotate any exposed credentials this week, then schedule the software upgrade in your next change window.

Why it matters:

  • Audit logs on affected TelePresence CE and RoomOS devices store SIP media credentials in clear text once that specific logging option is enabled, turning a diagnostic feature into a credential store.
  • Both on-device logs and logs held in Webex Cloud for cloud-aware deployments are exposed, so the blast radius includes cloud-side storage as well as the endpoint itself.
  • Any admin-level account, including one with narrower intended scope, could use this to pull credentials for confidential information that may include personally identifiable information.
  • Releases 9 and 10 have no dedicated patch; anyone still running those must migrate outright rather than apply a point fix.

Now / Next / Later:

  • Now: Check every TelePresence CE and RoomOS deployment for whether SIP media component logging has been explicitly enabled; it’s off by default so most estates may already be clear.
  • Next: Where logging is or has been enabled, rotate any credentials that may be sitting in existing audit logs (on-device and Webex Cloud) and upgrade release 11 devices to 11.32.2.1 or RoomOS July 2025 as appropriate.
  • Later: Migrate any devices still on release 9 or 10 to a supported, fixed release, and review who actually needs administrative credentials on these endpoints given exploitation depends entirely on holding that access.

Source