Input validation error in Cisco Systems, Inc products - CVE-2021-1418
Published: March 25, 2021
Vulnerability identifier: #VU51724
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-1418
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco Jabber for Windows
Cisco Jabber for MacOS
Cisco Jabber for Android and iOS
Cisco Jabber for Windows
Cisco Jabber for MacOS
Cisco Jabber for Android and iOS
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of message content. A remote authenticated attacker can send specially crafted XMPP messages and perform a denial of service (DoS) attack.
How to mitigate CVE-2021-1418
Install updates from vendor's website.