CVE-2020-3182
published 2020-03-04CVE-2020-3182: A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to…
PriorityP419medium4.3CVSS 3.1
AVAACLPRNUINSUCLINAN
EPSS
0.51%
39.8th percentile
A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnerability exists because sensitive information is included in the mDNS reply. An attacker could exploit this vulnerability by doing an mDNS query for a particular service against an affected device. A successful exploit could allow the attacker to gain access to sensitive information.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_webex_meetings | >= unspecified < n/a | n/a |
| cisco | webex_meetings | <= 40.1.8.5 | — |
| cisco | webex_meetings | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.04.3MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Webex Meetings Client for MacOS Information Disclosure Vulnerability
vendor_cisco·2020-03-04·CVSS 4.3
CVE-2020-3182 [MEDIUM] CWE-200 Cisco Webex Meetings Client for MacOS Information Disclosure Vulnerability
Cisco Webex Meetings Client for MacOS Information Disclosure Vulnerability
A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running.
The vulnerability exists because sensitive information is included in the mDNS reply. An attacker could exploit this vulnerability by doing an mDNS query for a particular service against an affected device. A successful exploit could allow the attacker to gain access to sensitive information.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory
Cisco
Cisco Webex Meetings Client for MacOS Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3182 Cisco Webex Meetings Client for MacOS Information Disclosure Vulnerability
CVE-2020-3182: Cisco Webex Meetings Client for MacOS Information Disclosure Vulnerability
A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnerability exists because sensitive information is included in the mDNS reply. An attacker could exploit this vulnerability by doing an mDNS query for a particular service against an affected device. A successful exploit could allow the attacker to gain access to sensitive information. There are no
CVSS: 3.0
CWE: CWE-200, CWE-200
Bug IDs: CSCvr98226
GHSA
GHSA-gx8j-3gxx-r6x6: A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent at
ghsa_unreviewed·2022-05-24
CVE-2020-3182 [LOW] GHSA-gx8j-3gxx-r6x6: A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent at
A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnerability exists because sensitive information is included in the mDNS reply. An attacker could exploit this vulnerability by doing an mDNS query for a particular service against an affected device. A successful exploit could allow the attacker to gain access to sensitive information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-03-04
Published