Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86c7-v7v4-whcp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a malicious UCF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit would cause the application to quit unexpectedly.

A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a malicious UCF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit would cause the application to quit unexpectedly.

EPSS

Процентиль: 55%
0.00321
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.5
nvd
больше 5 лет назад

A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a malicious UCF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit would cause the application to quit unexpectedly.

CVSS3: 5.5
fstec
около 6 лет назад

Уязвимость веб-интерфейса программного обеспечения для веб-конференцсвязи Cisco Webex Events, Cisco Webex Meeting Center, Cisco Webex Support Center, Cisco Webex Training Center, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 55%
0.00321
Низкий

Дефекты

CWE-20