Known vulnerabilities in Cisco Jabber for Windows
Vendor:
Cisco Systems, Inc
Software:
Cisco Jabber for Windows
Software CPE:
cpe:2.3:a:cisco_systems:cisco_jabber_for_windows:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
13
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (13)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU67953 - Exposure of resource to wrong sphere CVE-2022-20917 |
CWE-668 | Low | 12.6.6, 12.7.6, 12.8.7, 12.9.7, 14.0.5, 14.1.3 | 06.10.2022 |
SB2022100613 |
||
| #VU54207 - Resource Management Errors CVE-2021-1570 |
CWE-399 | Low | 14.0.1 | 17.06.2021 |
SB2021061718 |
||
| #VU54206 - Insufficiently Protected Credentials CVE-2021-1569 |
CWE-522 | Medium | 14.0.1 | 17.06.2021 |
SB2021061718 |
||
| #VU51728 - Improper Control of Generation of Code ('Code Injection') CVE-2021-1469 |
CWE-94 | Low | 12.1.5, 12.5.4, 12.6.5, 12.7.4, 12.8.5, 12.9.5 | 25.03.2021 |
SB2021032514 |
||
| #VU51727 - Improper Certificate Validation CVE-2021-1471 |
CWE-295 | Medium | 12.1.5, 12.5.4, 12.6.5, 12.7.4, 12.8.5, 12.9.5 | 25.03.2021 |
SB2021032514 |
||
| #VU51724 - Improper input validation CVE-2021-1418 |
CWE-20 | Low | 12.1.5, 12.5.4, 12.6.5, 12.7.4, 12.8.5, 12.9.5 | 25.03.2021 |
SB2021032514 |
||
| #VU51723 - Exposure of sensitive information to an unauthorized actor CVE-2021-1417 |
CWE-200 | Low | 12.1.5, 12.5.4, 12.6.5, 12.7.4, 12.8.5, 12.9.5 | 25.03.2021 |
SB2021032514 |
||
| #VU51722 - Improper Control of Generation of Code ('Code Injection') CVE-2021-1411 |
CWE-94 | Medium | 12.1.5, 12.5.4, 12.6.5, 12.7.4, 12.8.5, 12.9.5 | 25.03.2021 |
SB2021032514 |
||
| #VU48951 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2020-27134 |
CWE-89 | Medium | 12.1.4, 12.5.3, 12.6.4, 12.7.3, 12.8.4, 12.9.3 | 14.12.2020 |
SB2020121403 |
||
| #VU48950 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2020-27133 |
CWE-78 | High | 12.1.4, 12.5.3, 12.6.4, 12.7.3, 12.8.4, 12.9.3 | 14.12.2020 |
SB2020121403 |
||
| #VU48949 - Exposure of sensitive information to an unauthorized actor CVE-2020-27132 |
CWE-200 | Medium | 12.1.4, 12.5.3, 12.6.4, 12.7.3, 12.8.4, 12.9.3 | 14.12.2020 |
SB2020121403 |
||
| #VU48948 - Improper Access Control CVE-2020-27127 |
CWE-284 | Low | 12.1.4, 12.5.3, 12.6.4, 12.7.3, 12.8.4, 12.9.3 | 14.12.2020 |
SB2020121403 |
||
| #VU48947 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-26085 |
CWE-79 | Low | 12.1.4, 12.5.3, 12.6.4, 12.7.3, 12.8.4, 12.9.3 | 14.12.2020 |
SB2020121403 |