Input validation error in Cisco Systems, Inc products - CVE-2021-1418
Published: March 25, 2021
Vulnerability identifier: #VU51724
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1418
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of message content. A remote authenticated attacker can send specially crafted XMPP messages and perform a denial of service (DoS) attack.
Affected software
Cisco Jabber for Windows
Cisco Jabber for MacOS
Cisco Jabber for Android and iOS
Cisco Jabber for MacOS
Cisco Jabber for Android and iOS
How to mitigate CVE-2021-1418
Install updates from vendor's website.
Cisco Jabber for Windows - addressed in versions 12.1.5, 12.5.4, 12.6.5, 12.7.4, 12.8.5, 12.9.5
Cisco Jabber for MacOS - addressed in versions 12.8.7, 12.9.6
Cisco Jabber for MacOS - addressed in versions 12.8.7, 12.9.6