Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-3541

Опубликовано: 04 сент. 2020
Источник: nvd
CVSS3: 4.4
CVSS2: 2.1
EPSS Низкий

Описание

A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The vulnerability is due to unsafe logging of authentication requests by the affected software. An attacker could exploit this vulnerability by reading log files that are stored in the application directory. A successful exploit could allow the attacker to gain access to sensitive information, which could be used in further attacks.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:webex_meetings:*:*:*:*:*:windows:*:*
Версия до 39.5.25 (исключая)
cpe:2.3:a:cisco:webex_meetings:*:*:*:*:desktop:windows:*:*
Версия до 39.5.25 (исключая)
cpe:2.3:a:cisco:webex_meetings:*:*:*:*:*:windows:*:*
Версия от 40.6.0 (включая) до 40.6.6 (исключая)
cpe:2.3:a:cisco:webex_meetings:*:*:*:*:desktop:windows:*:*
Версия от 40.6.0 (включая) до 40.6.6 (исключая)
cpe:2.3:a:cisco:webex_teams:*:*:*:*:*:windows:*:*
Версия до 3.0.15711.0 (исключая)

EPSS

Процентиль: 19%
0.00062
Низкий

4.4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200
CWE-532

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The vulnerability is due to unsafe logging of authentication requests by the affected software. An attacker could exploit this vulnerability by reading log files that are stored in the application directory. A successful exploit could allow the attacker to gain access to sensitive information, which could be used in further attacks.

CVSS3: 4.4
fstec
больше 5 лет назад

Уязвимость компонента ядра программного обеспечения для веб-конференцсвязи Cisco Webex Meetings Desktop App, Webex Meetings Client и Webex Teams для операционных систем Windows, позволяющих нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 19%
0.00062
Низкий

4.4 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-200
CWE-532