CVE Database
/

CVE-2020-3322

Back to search

CVE-2020-3322

Published: Jun 3, 2020

Modified: Nov 15, 2024

PUBLISHED

CVSS v3.1

3.3

LOW

Description

A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file.

VendorProductVersions

Cisco

Cisco Webex Network Recording Player

affected
unspecified - < 3.0 MR3 Security Patch 2
affected
unspecified - < 4.0 MR3

Cisco

Cisco Webex Player for Microsoft Windows

affected
unspecified - < 3.0 MR3 Security Patch 2
affected
unspecified - < 4.0 MR3

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now