PT-2018-8827 · Cisco · Cisco Webex Teams

Published

2018-10-05

·

Updated

2024-05-23

·

CVE-2018-0436

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cisco Webex Teams (affected versions not specified)
Description A vulnerability could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The issue exists because the affected software performs insufficient checks for associations between user accounts and organization accounts. An attacker with administrator or compliance officer privileges for one organization account could exploit this by using those privileges to view and modify data for another organization account. No customer data was impacted by this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0436

Affected Products

Cisco Webex Teams