CVE-2017-12360
published 2017-11-30CVE-2017-12360: A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (DoS)…
PriorityP418medium4.3CVSS 3.0
AVNACLPRNUIRSUCNINAL
EPSS
1.01%
59.0th percentile
A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by providing a user with a malicious WRF file via email or URL and convincing the user to open the file. A successful exploit could cause an affected player to crash, resulting in a DoS condition. This vulnerability affects Cisco WebEx Business Suite meeting sites, Cisco WebEx Meetings sites, and Cisco WebEx WRF players. Cisco Bug IDs: CSCve30294, CSCve30301.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meeting_center | — | — |
| cisco | webex_meeting_center | — | — |
| cisco | webex_meeting_center | — | — |
| cisco | webex_meeting_center | — | — |
| cisco | webex_network_recording_player | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco WebEx Network Recording Player Denial of Service Vulnerability
vendor_cisco·2017-11-30·CVSS 4.3
CVE-2017-12360 [MEDIUM] CWE-399 Cisco WebEx Network Recording Player Denial of Service Vulnerability
Cisco WebEx Network Recording Player Denial of Service Vulnerability
A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by providing a user with a malicious WRF file via email or URL and convincing the user to open the file. A successful exploit could cause an affected player to crash, resulting in a DoS condition.
Cisco WebEx players are applications that are used to play back WebEx meeting recordings that have been recorded by an online meeting attendee. The player can be automatically installed when the user accesses a recording file that is hosted on a WebEx server.
There are no workarounds that address this vulnerability.
Th
Cisco
Cisco WebEx Network Recording Player Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-12360 Cisco WebEx Network Recording Player Denial of Service Vulnerability
CVE-2017-12360: Cisco WebEx Network Recording Player Denial of Service Vulnerability
A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by providing a user with a malicious WRF file via email or URL and convincing the user to open the file. A successful exploit could cause an affected player to crash, resulting in a DoS condition. Cisco WebEx players are applications that are used to play back WebEx meeting recordings that have been recorded by an online meeting attendee. The player can be automatically installed when the user accesses a recording file that is hosted on a WebEx server. There are no
CVSS: 3.0
CWE: CWE-399, CWE-399
Bug
GHSA
GHSA-mc3f-xxmw-v7w9: A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (D
ghsa_unreviewed·2022-05-13
CVE-2017-12360 [MEDIUM] GHSA-mc3f-xxmw-v7w9: A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (D
A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by providing a user with a malicious WRF file via email or URL and convincing the user to open the file. A successful exploit could cause an affected player to crash, resulting in a DoS condition. This vulnerability affects Cisco WebEx Business Suite meeting sites, Cisco WebEx Meetings sites, and Cisco WebEx WRF players. Cisco Bug IDs: CSCve30294, CSCve30301.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-11-30
Published