Information disclosure in Cisco Systems, Inc products - CVE-2020-3541

 

Information disclosure in Cisco Systems, Inc products - CVE-2020-3541

Published: September 4, 2020


Vulnerability identifier: #VU46278
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3541
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to unsafe logging of authentication requests by the affected software. A local administrator can read log files that are stored in the application directory and gain unauthorized access to sensitive information on the system.


Affected software

Cisco Webex Meetings Client for Windows
Cisco Webex Teams
Cisco Webex Meetings Desktop App

How to mitigate CVE-2020-3541

Install updates from vendor's website.

Cisco Webex Meetings Client for Windows - addressed in versions 39.5.25, 40.6.6
Cisco Webex Meetings Desktop App - addressed in versions 39.5.25, 40.6.6
Cisco Webex Teams - update to 3.0.15711.0

External References

Related Security Bulletins