PT-2018-8827 · Cisco · Cisco Webex Teams

Publicado

2018-10-05

·

Atualizado

2024-05-23

·

CVE-2018-0436

CVSS v3.1

8.7

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Webex Teams (affected versions not specified)
Description A vulnerability could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The issue exists because the affected software performs insufficient checks for associations between user accounts and organization accounts. An attacker with administrator or compliance officer privileges for one organization account could exploit this by using those privileges to view and modify data for another organization account. No customer data was impacted by this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-0436

Produtos afetados

Cisco Webex Teams