PT-2020-2902 · Cisco · Cisco Webex Player+1

Published

2020-06-03

·

Updated

2021-10-19

·

CVE-2020-3322

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Webex Network Recording Player (affected versions not specified) Cisco Webex Player (affected versions not specified)
Description The issue exists due to insufficient validation of certain elements within Webex recordings stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this by sending a malicious ARF or WRF file to a user through a link or email attachment, persuading them to open it with the affected software. A successful exploit could cause the Webex player application to crash when trying to view the malicious file, resulting in a Denial of Service (DoS) condition.
Recommendations For Cisco Webex Network Recording Player, consider disabling the playback of ARF and WRF files until a patch is available. For Cisco Webex Player, restrict access to opening files from untrusted sources to minimize the risk of exploitation. As a temporary workaround, avoid opening suspicious links or email attachments that could contain malicious ARF or WRF files.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03059
CVE-2020-3322

Affected Products

Cisco Webex Network Recording Player
Cisco Webex Player