Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1467

Опубликовано: 08 апр. 2021
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:webex_meetings:*:*:*:*:*:android:*:*
Версия до 41.3 (исключая)

EPSS

Процентиль: 29%
0.00107
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other

Связанные уязвимости

CVSS3: 4.3
github
больше 3 лет назад

A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user.

CVSS3: 4.3
fstec
почти 5 лет назад

Уязвимость программного обеспечения для веб-конференцсвязи Cisco Webex Meetings для Android, связанная с недостатками контроля доступа, позволяющая нарушителю изменить аватар целевого пользователя

EPSS

Процентиль: 29%
0.00107
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other