Security restrictions bypass in Cisco Webex Teams - CVE-2018-0436

 

Security restrictions bypass in Cisco Webex Teams - CVE-2018-0436

Published: September 5, 2018 / Updated: September 6, 2018


Vulnerability identifier: #VU14674
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0436
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to bypass security restrictions.

The vulnerability exists due to the affected software performs insufficient checks for associations between user accounts and organization accounts. A remote attacker who has administrator or compliance officer privileges for one organization account can use those privileges to view and modify data for another organization account.


Affected software

Cisco Webex Teams

How to mitigate CVE-2018-0436

Install update from vendor's website.


External References

Related Security Bulletins