#VU24163 Input validation error in Cisco Systems, Inc products - CVE-2020-3116
Published: January 9, 2020
Vulnerability identifier: #VU24163
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-3116
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Cisco WebEx Event Center
Cisco Webex Support Center
Cisco WebEx Meeting Center
Cisco WebEx Training Center
Cisco WebEx Event Center
Cisco Webex Support Center
Cisco WebEx Meeting Center
Cisco WebEx Training Center
Software vendor:
Cisco Systems, Inc
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of Universal Communications Format UCF media files. A remote attacker can trick a victim to open a specially crafted UCF file and cause the application to quit unexpectedly.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.