CVE-2018-0380Cisco Webex Meetings Online vulnerability

CWE-3995 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
0.4%
top 41.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 18
Latest updateMay 13

Description

Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by providing a user with a malicious .arf or .wrf file via email or URL and convincing the user to launch the file in the Webex recording players. Exploitation of these vulnerabilities could cause an affected player to crash, resulting in a denial of service (DoS) condition. The Cisco Webex players a

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

NVDcisco/webex_meetings_online5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-2pxj-rx8j-9775: Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files2022-05-13
CVEList
CVE-2018-0380: Multiple vulnerabilities exist in the Cisco Webex Network Recording Player for Advanced Recording Format (ARF) and Webex Recording Format (WRF) files2018-07-18

📋Vendor Advisories

1
Cisco
Cisco Webex Network Recording Players Denial of Service Vulnerabilities2018-07-18

💬Community

1
Bugzilla
CVE-2017-15125 cloudforms: XSS in self-service UI snapshot feature2017-11-24
CVE-2018-0380 — Cisco vulnerability | cvebase