SB2018020801 - Security restrictions bypass in Cisco Spark
Published: February 8, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2018-0119)
The vulnerability allows a remote authenticated attacker to bypass security restrictions on the target system.
The vulnerability exists due to the improper display of user-account tokens generated in the system. A remote attacker can log in to the device with a token in use by another account and cause a partial impact to the device's confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.