Information disclosure in Cisco Systems, Inc products - CVE-2020-3541
Published: September 4, 2020
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to unsafe logging of authentication requests by the affected software. A local administrator can read log files that are stored in the application directory and gain unauthorized access to sensitive information on the system.
Affected software
Cisco Webex Teams
Cisco Webex Meetings Desktop App
How to mitigate CVE-2020-3541
Cisco Webex Meetings Desktop App - addressed in versions 39.5.25, 40.6.6
Cisco Webex Teams - update to 3.0.15711.0