Input validation error in Cisco Systems, Inc products - CVE-2020-3116
Published: January 9, 2020
Vulnerability identifier: #VU24163
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-3116
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco WebEx Event Center
Cisco Webex Support Center
Cisco WebEx Meeting Center
Cisco WebEx Training Center
Cisco WebEx Event Center
Cisco Webex Support Center
Cisco WebEx Meeting Center
Cisco WebEx Training Center
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of Universal Communications Format UCF media files. A remote attacker can trick a victim to open a specially crafted UCF file and cause the application to quit unexpectedly.
How to mitigate CVE-2020-3116
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.