CVE-2015-6384
published 2015-12-05CVE-2015-6384: The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, which allows attackers to bypass intended…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.51%
71.5th percentile
The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka Bug ID CSCuw86442.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings | — | — |
| cisco | webex_meetings_for_android_custom_permissions | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5fc6-3qhh-jxxg: The Cisco WebEx Meetings application before 8
ghsa_unreviewed·2022-05-17
CVE-2015-6384 [MEDIUM] GHSA-5fc6-3qhh-jxxg: The Cisco WebEx Meetings application before 8
The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka Bug ID CSCuw86442.
Cisco
Cisco WebEx Meetings for Android Custom Permissions Vulnerability
vendor_cisco·2015-12-02·CVSS 4.3
CVE-2015-6384 [MEDIUM] CWE-264 Cisco WebEx Meetings for Android Custom Permissions Vulnerability
Cisco WebEx Meetings for Android Custom Permissions Vulnerability
A vulnerability in the custom application permissions handling for Cisco WebEx Meetings for Android could allow an unauthenticated, remote attacker to change platform-specific permissions of a custom application.
The vulnerability is due to the way custom application permissions are assigned at initialization. An attacker could exploit this vulnerability by downloading a malicious Android application to the mobile device. An exploit could allow the attacker to utilize the custom application to silently acquire the same permissions as the WebEx application.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the
Cisco
Cisco WebEx Meetings for Android Custom Permissions Vulnerability
vendor_cisco
CVE-2015-6384 Cisco WebEx Meetings for Android Custom Permissions Vulnerability
CVE-2015-6384: Cisco WebEx Meetings for Android Custom Permissions Vulnerability
A vulnerability in the custom application permissions handling for Cisco WebEx Meetings for Android could allow an unauthenticated, remote attacker to change platform-specific permissions of a custom application. The vulnerability is due to the way custom application permissions are assigned at initialization. An attacker could exploit this vulnerability by downloading a malicious Android application to the mobile device. An exploit could allow the attacker to utilize the custom application to silently acquire the same permissions as the WebEx application. Cisco has released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs: CSCuw86442
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-12-05
Published