CVE-2020-3495
published 2020-09-04CVE-2020-3495: A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper…
PriorityP274high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
62.12%
99.1th percentile
A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages to the affected software. A successful exploit could allow the attacker to cause the application to execute arbitrary programs on the targeted system with the privileges of the user account that is running the Cisco Jabber client software, possibly resulting in arbitrary code execution.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_jabber | — | — |
| cisco | jabber | >= 12.1 < 12.1.3 | 12.1.3 |
| cisco | jabber | >= 12.5 < 12.5.2 | 12.5.2 |
| cisco | jabber | >= 12.6 < 12.6.3 | 12.6.3 |
| cisco | jabber | >= 12.7 < 12.7.2 | 12.7.2 |
| cisco | jabber | >= 12.8 < 12.8.3 | 12.8.3 |
| cisco | jabber | >= 12.9 < 12.9.1 | 12.9.1 |
| cisco | jabber_for_windows_message_handling | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/CLIENT_REQUEST/
bytes
.CallCppFunction|28|
snort
alert http any any -> [$HTTP_SERVERS,$HOME_NET] any (msg:"ET EXPLOIT Possible Cisco Jabber RCE Inbound (CVE-2020-3495)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/CLIENT_REQUEST/"; http.request_body; content:".CallCppFunction|28|"; fast_pattern; reference:url,watchcom.no/nyheter/nyhetsarkiv/uncovers-cisco-jabber-vulnerabilities/; reference:cve,2020-3495; classtype:attempted-admin; sid:2030837; rev:1; metadata:created_at 2020_09_05, cve CVE_2020_3495, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_09_05;)
- →Exploit traffic arrives as an HTTP POST to the /CLIENT_REQUEST/ URI path, targeting HTTP servers or internal hosts. Inspect HTTP request bodies for the string '.CallCppFunction|28|' as a fast-pattern indicator of exploitation.
- →The attack vector is specially crafted XMPP messages sent to Cisco Jabber for Windows. Monitor XMPP traffic for anomalous or unexpected message content targeting Jabber clients. ↗
- →Exploitation requires an authenticated remote attacker; monitor for unexpected program execution spawned from the Cisco Jabber client process (running under the user account context). ↗
- →Emerging Threats rule SID 2030837 (ET EXPLOIT) covers inbound exploitation attempts; deploy at both Perimeter and Internal network segments for coverage.
- ·The vulnerability is due to improper validation of message contents; no workarounds exist — patching is the only remediation. ↗
- ·The ET rule targets inbound HTTP traffic to $HTTP_SERVERS and $HOME_NET; ensure these Snort/Suricata variables are correctly scoped to your Jabber server infrastructure for accurate detection.
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fgm2-2fhw-x8fx: A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code
ghsa_unreviewed·2022-05-24
CVE-2020-3495 [HIGH] CWE-20 GHSA-fgm2-2fhw-x8fx: A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code
A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages to the affected software. A successful exploit could allow the attacker to cause the application to execute arbitrary programs on the targeted system with the privileges of the user account that is running the Cisco Jabber client software, possibly resulting in arbitrary code execution.
Cisco
Cisco Jabber for Windows Message Handling Arbitrary Code Execution Vulnerability
vendor_cisco·2020-09-02·CVSS 9.9
CVE-2020-3495 [CRITICAL] CWE-20 Cisco Jabber for Windows Message Handling Arbitrary Code Execution Vulnerability
Cisco Jabber for Windows Message Handling Arbitrary Code Execution Vulnerability
A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code.
The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages to the affected software. A successful exploit could allow the attacker to cause the application to execute arbitrary programs on the targeted system with the privileges of the user account that is running the Cisco Jabber client software, possibly resulting in arbitrary code execution.
Cisco has released software updates that address this vulnerability. There are no workarounds that address thi
Cisco
Cisco Jabber for Windows Message Handling Arbitrary Code Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3495 Cisco Jabber for Windows Message Handling Arbitrary Code Execution Vulnerability
CVE-2020-3495: Cisco Jabber for Windows Message Handling Arbitrary Code Execution Vulnerability
A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages to the affected software. A successful exploit could allow the attacker to cause the application to execute arbitrary programs on the targeted system with the privileges of the user account that is running the Cisco Jabber client software, possibly resulting in arbitrary code execution. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE:
Suricata
ET EXPLOIT Possible Cisco Jabber RCE Inbound (CVE-2020-3495)
suricata·2020-09-05·CVSS 9.9
CVE-2020-3495 [CRITICAL] ET EXPLOIT Possible Cisco Jabber RCE Inbound (CVE-2020-3495)
ET EXPLOIT Possible Cisco Jabber RCE Inbound (CVE-2020-3495)
Rule: alert http any any -> [$HTTP_SERVERS,$HOME_NET] any (msg:"ET EXPLOIT Possible Cisco Jabber RCE Inbound (CVE-2020-3495)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/CLIENT_REQUEST/"; http.request_body; content:".CallCppFunction|28|"; fast_pattern; reference:url,watchcom.no/nyheter/nyhetsarkiv/uncovers-cisco-jabber-vulnerabilities/; reference:cve,2020-3495; classtype:attempted-admin; sid:2030837; rev:1; metadata:created_at 2020_09_05, cve CVE_2020_3495, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_09_05;)
No public exploits indexed.
2020-09-04
Published