SB2018090612 - Security restrictions bypass in Cisco Webex Teams
Published: September 6, 2018
Security Bulletin ID
SB2018090612
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: CVE-2018-0436)
The vulnerability allows a remote authenticated attacker to bypass security restrictions.
The vulnerability exists due to the affected software performs insufficient checks for associations between user accounts and organization accounts. A remote attacker who has administrator or compliance officer privileges for one organization account can use those privileges to view and modify data for another organization account.
Remediation
Install update from vendor's website.