Exposure of Resource to Wrong Sphere in Cisco Systems, Inc products - CVE-2022-20917

 

Exposure of Resource to Wrong Sphere in Cisco Systems, Inc products - CVE-2022-20917

Published: October 6, 2022


Vulnerability identifier: #VU67953
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20917
CWE-ID: CWE-668
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the system.

The vulnerability exists due to the improper handling of nested Extensible Messaging and Presence Protocol (XMPP) messages. A remote user can send specially crafted XMPP messages and cause the Jabber client application to perform unsafe actions.


Affected software

Cisco Jabber for iOS MAM
Cisco Jabber for Android MAM
Cisco Jabber for Android and iOS
Cisco Jabber for Windows
Cisco Jabber for MacOS

How to mitigate CVE-2022-20917

Install updates from vendor's website.

Cisco Jabber for iOS MAM - update to 14.1.4
Cisco Jabber for Android MAM - update to 14.1.4
Cisco Jabber for Android and iOS - update to 14.1.4
Cisco Jabber for Windows - addressed in versions 12.6.6, 12.7.6, 12.8.7, 12.9.7, 14.0.5, 14.1.3
Cisco Jabber for MacOS - addressed in versions 12.8.8, 12.9.8, 14.0.5, 14.1.3

External References

Related Security Bulletins