CVE-2024-20396
published 2024-07-17CVE-2024-20396: A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This…
PriorityP336medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.42%
33.7th percentile
A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information.
This vulnerability exists because the affected application does not safely handle file protocol handlers. An attacker could exploit this vulnerability by persuading a user to follow a link that is designed to cause the application to send requests. If the attacker can observe transmitted traffic in a privileged network position, a successful exploit could allow the attacker to capture sensitive information, including credential information, from the requests.
Affected
89 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
| cisco | cisco_webex_teams | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-67ww-939x-f5pp: A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information
ghsa_unreviewed·2024-07-17
CVE-2024-20396 [MEDIUM] CWE-200 GHSA-67ww-939x-f5pp: A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information
A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information.
This vulnerability exists because the affected application does not safely handle file protocol handlers. An attacker could exploit this vulnerability by persuading a user to follow a link that is designed to cause the application to send requests. If the attacker can observe transmitted traffic in a privileged network position, a successful exploit could allow the attacker to capture sensitive information, including credential information, from the requests.
Cisco
Cisco Webex App Vulnerabilities
vendor_cisco·2024-07-17·CVSS 6.4
CVE-2024-20395 [MEDIUM] CWE-200 Cisco Webex App Vulnerabilities
Cisco Webex App Vulnerabilities
Multiple vulnerabilities in Cisco Webex App could allow an unauthenticated attacker to gain access to sensitive credential information.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. The updates are part of the Cisco Webex service, and no customer action is necessary to get these software updates. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-ZjNm8X8j
Cisco
Cisco Webex App Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2024-20396 Cisco Webex App Vulnerabilities
CVE-2024-20396: Cisco Webex App Vulnerabilities
Multiple vulnerabilities in Cisco Webex App could allow an unauthenticated attacker to gain access to sensitive credential information. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-200, CWE-523, CWE-200, CWE-523
Bug IDs: CSCwj36941, CSCwj36943, CSCwj36947, CSCwj36941, CSCwj36943
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-07-17
Published