Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-20763

Опубликовано: 06 апр. 2022
Источник: nvd
CVSS3: 5.4
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attacker to inject arbitrary Java code. This vulnerability is due to improper deserialization of Java code within login requests. An attacker could exploit this vulnerability by sending malicious login requests to the Cisco Webex Meetings service. A successful exploit could allow the attacker to inject arbitrary Java code and take arbitrary actions within the Cisco Webex Meetings application.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:webex_meetings_online:wbs42.2.1-1:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00479
Низкий

5.4 Medium

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-502
CWE-502

Связанные уязвимости

CVSS3: 8.8
github
почти 4 года назад

A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attacker to inject arbitrary Java code. This vulnerability is due to improper deserialization of Java code within login requests. An attacker could exploit this vulnerability by sending malicious login requests to the Cisco Webex Meetings service. A successful exploit could allow the attacker to inject arbitrary Java code and take arbitrary actions within the Cisco Webex Meetings application.

CVSS3: 5.4
fstec
больше 4 лет назад

Уязвимость функции авторизации программного обеспечения веб-конференцсвязи Cisco Webex Meetings, позволяющая нарушителю внедрить произвольный код Java и выполнить произвольные действия

EPSS

Процентиль: 65%
0.00479
Низкий

5.4 Medium

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-502
CWE-502