cbcvebase.
CVE-2022-20917
published 2023-09-15

CVE-2022-20917: A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote…

PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.89%
55.1th percentile
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to the improper handling of nested XMPP messages within requests that are sent to the Cisco Jabber client software. An attacker could exploit this vulnerability by connecting to an XMPP messaging server and sending crafted XMPP messages to an affected Jabber client. A successful exploit could allow the attacker to manipulate the content of XMPP messages, possibly allowing the attacker to cause the Jabber client application to perform unsafe actions.

Affected

156 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber
ciscocisco_jabber

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.