CVE-2020-3502
published 2020-08-17CVE-2020-3502: Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted…
PriorityP418medium4.1CVSS 3.1
AVNACLPRLUIRSCCLINAN
EPSS
1.02%
59.3th percentile
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker with a valid Webex account could exploit these vulnerabilities by persuading a user to follow a URL that is designed to return malicious path parameters to the affected software. A successful exploit could allow the attacker to obtain restricted information from other Webex users.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_webex_meetings | — | — |
| cisco | webex_meetings | < 39.5.24 | 39.5.24 |
| cisco | webex_meetings | — | — |
| cisco | webex_meetings | >= 40.4.0 < 40.4.6 | 40.4.6 |
| cisco | webex_meetings | >= 40.4.10 < 40.6.0 | 40.6.0 |
| cisco | webex_meetings_desktop_app | — | — |
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server | — | — |
CVSS provenance
nvdv3.14.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
vendor_cisco4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Webex Meetings Desktop App Information Disclosure Vulnerabilities
vendor_cisco·2020-08-05·CVSS 4.1
CVE-2020-3501 [MEDIUM] CWE-20 Cisco Webex Meetings Desktop App Information Disclosure Vulnerabilities
Cisco Webex Meetings Desktop App Information Disclosure Vulnerabilities
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users.
These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker with a valid Webex account could exploit these vulnerabilities by persuading a user to follow a URL that is designed to return malicious path parameters to the affected software. A successful exploit could allow the attacker to obtain restricted information from other Webex users.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilit
Cisco
Cisco Webex Meetings Desktop App Information Disclosure Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2020-3502 Cisco Webex Meetings Desktop App Information Disclosure Vulnerabilities
CVE-2020-3502: Cisco Webex Meetings Desktop App Information Disclosure Vulnerabilities
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker with a valid Webex account could exploit these vulnerabilities by persuading a user to follow a URL that is designed to return malicious path parameters to the affected software. A successful exploit could allow the attacker to obtain restricted information from other Webex users. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.1
CWE: CWE-20, CWE-20
GHSA
GHSA-h8v3-xwjj-m863: Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted
ghsa_unreviewed·2022-05-24
CVE-2020-3502 [LOW] GHSA-h8v3-xwjj-m863: Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker with a valid Webex account could exploit these vulnerabilities by persuading a user to follow a URL that is designed to return malicious path parameters to the affected software. A successful exploit could allow the attacker to obtain restricted information from other Webex users.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-08-17
Published