PT-2020-1954 · Cisco · Cisco Webex Meetings Client

Hd Moore

·

Published

2020-03-04

·

Updated

2020-05-04

·

CVE-2020-3182

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Webex Meetings Client for MacOS (affected versions not specified)
Description A vulnerability in the multicast DNS (mDNS) protocol configuration could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnerability exists because sensitive information is included in the mDNS reply. An attacker could exploit this vulnerability by doing an mDNS query for a particular service against an affected device. A successful exploit could allow the attacker to gain access to sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01233
CVE-2020-3182

Affected Products

Cisco Webex Meetings Client