Cisco Security Advisory - Cisco Jabber and Webex Client Software Shared File Manipulation Vulnerability

Started by Netwörkheäd, June 16, 2021, 12:11:52 PM

Previous topic - Next topic

Netwörkheäd

Cisco Jabber and Webex Client Software Shared File Manipulation Vulnerability

A vulnerability in Cisco Jabber and Cisco Webex (formerly Teams) could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface.


The vulnerability exists because the affected software mishandles character rendering. An attacker could exploit this vulnerability by sharing a file within the application interface. A successful exploit could allow the attacker to modify how the shared file name displays within the interface, which could allow the attacker to conduct phishing or spoofing attacks.


Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.


This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-teams-7ZMcXG99



     
         
Security Impact Rating:  Medium
   
   
       
CVE: CVE-2021-1242
Source: Cisco Jabber and Webex Client Software Shared File Manipulation Vulnerability
Let's not argue. Let's network!