Input validation error in Cisco Systems, Inc products - CVE-2020-3116

 

Input validation error in Cisco Systems, Inc products - CVE-2020-3116

Published: January 9, 2020


Vulnerability identifier: #VU24163
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3116
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of Universal Communications Format UCF media files. A remote attacker can trick a victim to open a specially crafted UCF file and cause the application to quit unexpectedly.


Affected software

Cisco WebEx Event Center
Cisco Webex Support Center
Cisco WebEx Meeting Center
Cisco WebEx Training Center

How to mitigate CVE-2020-3116

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins