cisco-sa-20200108-webex-centers-dos: Cisco Webex Centers Denial of Service Vulnerability
A vulnerability in the way Cisco Webex applications process Universal Communications Format (UCF) files could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of UCF media files. An attacker could exploit this vulnerability by sending a user a malicious UCF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit would cause the application to quit unexpectedly. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200108-webex-centers-dos
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20200108-webex-centers-dos?
The severity of cisco-sa-20200108-webex-centers-dos is classified as High due to its potential to cause a denial of service condition.
How do I fix cisco-sa-20200108-webex-centers-dos?
To fix cisco-sa-20200108-webex-centers-dos, update your Cisco Webex software to the latest version provided by Cisco.
What products are affected by cisco-sa-20200108-webex-centers-dos?
The affected product for cisco-sa-20200108-webex-centers-dos is the Cisco Webex application.
What type of vulnerability is cisco-sa-20200108-webex-centers-dos?
cisco-sa-20200108-webex-centers-dos is a denial of service (DoS) vulnerability.
How can an attacker exploit cisco-sa-20200108-webex-centers-dos?
An attacker can exploit cisco-sa-20200108-webex-centers-dos by sending specially crafted Universal Communications Format (UCF) files to the Cisco Webex application.