First published: Wed Apr 07 2021(Updated: )
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they are both participants. A successful exploit could allow the attacker to modify the avatar of the targeted user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-andro-iac-f3UR8frB
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Client |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-webex-andro-iac-f3UR8frB is classified as medium.
cisco-sa-webex-andro-iac-f3UR8frB is an improper authorization vulnerability.
An attacker can exploit cisco-sa-webex-andro-iac-f3UR8frB by sending a crafted request to modify another user's avatar.
cisco-sa-webex-andro-iac-f3UR8frB affects the Cisco Webex Meetings Client for Android.
To fix cisco-sa-webex-andro-iac-f3UR8frB, users should update to the latest version of the Cisco Webex Meetings Client.