Security restrictions bypass in Cisco Webex Teams



Published: 2018-09-06
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2018-0436
CWE-ID CWE-264
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Cisco Webex Teams
Client/Desktop applications / Office applications

Vendor Cisco Systems, Inc

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Security restrictions bypass

EUVDB-ID: #VU14674

Risk: Low

CVSSv3.1: 7.6 [CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-0436

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a remote authenticated attacker to bypass security restrictions.

The vulnerability exists due to the affected software performs insufficient checks for associations between user accounts and organization accounts. A remote attacker who has administrator or compliance officer privileges for one organization account can use those privileges to view and modify data for another organization account.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Cisco Webex Teams: All versions

External links

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-webex-id-mod


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to visit a specially crafted website or open a file.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###