CVE-2021-1467
published 2021-04-08CVE-2021-1467: A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.74%
50.5th percentile
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_webex_meetings | — | — |
| cisco | webex_meetings | < 41.3 | 41.3 |
| cisco | webex_meetings_for_android_avatar_modification | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Webex Meetings for Android Avatar Modification Vulnerability
vendor_cisco·2021-04-07·CVSS 4.3
CVE-2021-1467 [MEDIUM] CWE-284 Cisco Webex Meetings for Android Avatar Modification Vulnerability
Cisco Webex Meetings for Android Avatar Modification Vulnerability
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user.
This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex
Cisco
Cisco Webex Meetings for Android Avatar Modification Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1467 Cisco Webex Meetings for Android Avatar Modification Vulnerability
CVE-2021-1467: Cisco Webex Meetings for Android Avatar Modification Vulnerability
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-284, CWE-284
Bug IDs: CSCvw45870
GHSA
GHSA-m9p9-grq9-ph27: A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user
ghsa_unreviewed·2022-05-24
CVE-2021-1467 [MEDIUM] CWE-269 GHSA-m9p9-grq9-ph27: A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-04-08
Published