Executive Summary
Summary | |
---|---|
Title | Cisco Webex Teams Information Disclosure and Modification Vulnerability |
Informations | |||
---|---|---|---|
Name | cisco-sa-20180905-webex-id-mod | First vendor Publication | 2018-09-05 |
Vendor | Cisco | Last vendor Modification | 2018-09-05 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:S/C:P/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 5.5 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerability exists because the affected software performs insufficient checks for associations between user accounts and organization accounts. An attacker who has administrator or compliance officer privileges for one organization account could exploit this vulnerability by using those privileges to view and modify data for another organization account. No customer data was impacted by this vulnerability. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-webex-id-mod ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-webex-id-mod"] BEGIN PGP SIGNATURE iQJ5BAEBAgBjBQJbkADLXBxDaXNjbyBQcm9kdWN0IFNlY3VyaXR5IEluY2lkZW50 IFJlc3BvbnNlIFRlYW0gKENpc2NvIFBTSVJUIGtleSAyMDE4LTIwMTkpIDxwc2ly dEBjaXNjby5jb20+AAoJEJa12PPJBfczAG0P/iOXOfQWYTY1QXHex4QWc2NERe05 Bk0UftlH491FcYzy1Yzrj2sLsxCUmw9o20g+5sd1i1p3CPeHqBT/WFgWa0a8Hjwt YyKV5BSJPu5lU6+uotiJIQHLYvWYYKtBRFwXaRfbsncjTTZNv8NcIQaMHTaLuHAG O0bRxBbbQw2EOX5xEJFs/QWj37fegme9Jj/U27c74LoxL2Tl7OyPXv+5260LLZhq +ev2C59Md2zCKiE7X6Q2tkEn9L3webqep2qiFNAnWV1WeZD/mZZEmrO7q4IcQb9n HvIdIMR0lYhSi9gUq9ZL8vvl1N+fOCI6jwrIb6ol+F+cJtQaxtxH2KFOXGEWt+VU HDZH6oWBXF8ULgTEK2tAkLNz8EgU8Wl7sT5uHJmbvbqHsh3KZO6IzOnoXR3sAQet dr9KGAQSRXN16CPsBM+eW3lVP7AdWE+eXQNsBp+x1PClCvGvcCYK7c3ErCEJvxbh 7Sjik66g63U7ybN9MMi+u/1IPwwIqTi70FhCFrahR8JPvlZr2Lq27ifnYNLjmHtc +NysspxEUkmlMuODdn/ohArIrZJRKUPfQpMcofE37PEy0jrBSCMj26spUTBACOmj ecI3mH6nXWsBmYIWvR7/lYog38Tv+Wk31/aTd3G6eApAx6cz821WLDZqswmCeLqQ ZGGxvWzaj0lL81Ah =aWfp END PGP SIGNATURE _______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com |
Original Source
Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...) |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-269 | Improper Privilege Management |
CPE : Common Platform Enumeration
Alert History
Date | Informations |
---|---|
2019-01-09 17:20:59 |
|
2018-10-05 21:21:50 |
|
2018-09-05 21:19:44 |
|