SB2022090802 - Multiple Interpretations of UI Input in Cisco Webex Meetings App



SB2022090802 - Multiple Interpretations of UI Input in Cisco Webex Meetings App

Published: September 8, 2022

Security Bulletin ID SB2022090802
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Multiple Interpretations of UI Input (CVE-ID: CVE-2022-20863)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected software does not properly handle character rendering. A remote attacker can send specially crafted messages and modify the display of links or other content within the interface.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.