Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1242

Опубликовано: 13 янв. 2021
Источник: nvd
CVSS3: 4.3
CVSS2: 4.3
EPSS Низкий

Описание

A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface. The vulnerability exists because the affected software mishandles character rendering. An attacker could exploit this vulnerability by sharing a file within the application interface. A successful exploit could allow the attacker to modify how the shared file name displays within the interface, which could allow the attacker to conduct phishing or spoofing attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:webex_teams:*:*:*:*:*:*:*:*
Версия до 40.12.0.17293 (исключая)

EPSS

Процентиль: 58%
0.00373
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-450
NVD-CWE-noinfo

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface. The vulnerability exists because the affected software mishandles character rendering. An attacker could exploit this vulnerability by sharing a file within the application interface. A successful exploit could allow the attacker to modify how the shared file name displays within the interface, which could allow the attacker to conduct phishing or spoofing attacks.

CVSS3: 4.3
fstec
около 5 лет назад

Уязвимость программного средства совместной работы Cisco Webex Teams, связанная с ошибками при обработке изображений различных символов, позволяющая нарушителю манипулировать именами файлов в интерфейсе обмена сообщениями

EPSS

Процентиль: 58%
0.00373
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-450
NVD-CWE-noinfo