CVE-2021-1569
published 2021-06-16CVE-2021-1569: Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.80%
52.2th percentile
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_jabber | — | — |
| cisco | jabber | >= 12.9 < 12.9.6.55898 | 12.9.6.55898 |
| cisco | jabber | >= 14.0 < 14.0.1.55914 | 14.0.1.55914 |
| cisco | jabber_desktop_and_mobile | — | — |
| redis | redis | >= 2.6.0 < 3.1.1 | 3.1.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5g7p-v93f-fjp9: Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access se
ghsa_unreviewed·2022-05-24
CVE-2021-1569 [MEDIUM] CWE-20 GHSA-5g7p-v93f-fjp9: Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access se
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.
GHSA
Node-Redis potential exponential regex in monitor mode
ghsa·2021-04-27
CVE-2021-29469 [HIGH] CWE-400 Node-Redis potential exponential regex in monitor mode
Node-Redis potential exponential regex in monitor mode
### Impact
When a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a denial of service.
### Patches
The problem was fixed in commit [`2d11b6d`](https://github.com/NodeRedis/node-redis/commit/2d11b6dc9b9774464a91fb4b448bad8bf699629e) and was released in version `3.1.1`.
### References
#1569 (GHSL-2021-026)
Cisco
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
vendor_cisco·2021-06-16·CVSS 6.5
CVE-2021-1569 [MEDIUM] CWE-399 Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-GuC5mLwG
Cisco
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1569 Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
CVE-2021-1569: Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-399, CWE-522, CWE-399, CWE-522
Bug IDs: CSCvy20799, CSCvy20801, CSCvy20799, CSCvy20801
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-06-16
Published