Executive Summary

Summary
Title Cisco Webex Teams Information Disclosure and Modification Vulnerability
Informations
Name cisco-sa-20180905-webex-id-mod First vendor Publication 2018-09-05
Vendor Cisco Last vendor Modification 2018-09-05
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:S/C:P/I:P/A:N)
Cvss Base Score 5.5 Attack Range Network
Cvss Impact Score 4.9 Attack Complexity Low
Cvss Expoit Score 8 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization.

The vulnerability exists because the affected software performs insufficient checks for associations between user accounts and organization accounts. An attacker who has administrator or compliance officer privileges for one organization account could exploit this vulnerability by using those privileges to view and modify data for another organization account.

No customer data was impacted by this vulnerability.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-webex-id-mod ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-webex-id-mod"]

BEGIN PGP SIGNATURE

iQJ5BAEBAgBjBQJbkADLXBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50 IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly dEBjaXNjby5jb20+AAoJEJa12PPJBfczAG0P/iOXOfQWYTY1QXHex4QWc2NERe05 Bk0UftlH491FcYzy1Yzrj2sLsxCUmw9o20g+5sd1i1p3CPeHqBT/WFgWa0a8Hjwt YyKV5BSJPu5lU6+uotiJIQHLYvWYYKtBRFwXaRfbsncjTTZNv8NcIQaMHTaLuHAG O0bRxBbbQw2EOX5xEJFs/QWj37fegme9Jj/U27c74LoxL2Tl7OyPXv+5260LLZhq +ev2C59Md2zCKiE7X6Q2tkEn9L3webqep2qiFNAnWV1WeZD/mZZEmrO7q4IcQb9n HvIdIMR0lYhSi9gUq9ZL8vvl1N+fOCI6jwrIb6ol+F+cJtQaxtxH2KFOXGEWt+VU HDZH6oWBXF8ULgTEK2tAkLNz8EgU8Wl7sT5uHJmbvbqHsh3KZO6IzOnoXR3sAQet dr9KGAQSRXN16CPsBM+eW3lVP7AdWE+eXQNsBp+x1PClCvGvcCYK7c3ErCEJvxbh 7Sjik66g63U7ybN9MMi+u/1IPwwIqTi70FhCFrahR8JPvlZr2Lq27ifnYNLjmHtc +NysspxEUkmlMuODdn/ohArIrZJRKUPfQpMcofE37PEy0jrBSCMj26spUTBACOmj ecI3mH6nXWsBmYIWvR7/lYog38Tv+Wk31/aTd3G6eApAx6cz821WLDZqswmCeLqQ ZGGxvWzaj0lL81Ah =aWfp END PGP SIGNATURE

_______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-269 Improper Privilege Management

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 9

Alert History

If you want to see full details history, please login or register.
0
1
2
Date Informations
2019-01-09 17:20:59
  • Multiple Updates
2018-10-05 21:21:50
  • Multiple Updates
2018-09-05 21:19:44
  • First insertion