Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-3116

Опубликовано: 23 сент. 2020
Источник: nvd
CVSS3: 5.5
CVSS3: 5.5
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a malicious UCF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit would cause the application to quit unexpectedly.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:webex_meetings_online:1.3.43:*:*:*:*:*:*:*
cpe:2.3:a:cisco:webex_meetings_server:4.0:-:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.00321
Низкий

5.5 Medium

CVSS3

5.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a malicious UCF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit would cause the application to quit unexpectedly.

CVSS3: 5.5
fstec
около 6 лет назад

Уязвимость веб-интерфейса программного обеспечения для веб-конференцсвязи Cisco Webex Events, Cisco Webex Meeting Center, Cisco Webex Support Center, Cisco Webex Training Center, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 55%
0.00321
Низкий

5.5 Medium

CVSS3

5.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20
CWE-20