PT-2020-2959 · Cisco · Cisco Webex Meetings Desktop App

Martin Rakhmanov

·

Published

2020-06-17

·

Updated

2021-08-06

·

CVE-2020-3347

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Webex Meetings Desktop App for Windows (affected versions not specified)
Description A vulnerability in the software could allow an authenticated, local attacker to gain access to sensitive information on an affected system. The issue is due to unsafe usage of shared memory used by the affected software. An attacker with permissions to view system memory could exploit this by running an application designed to read shared memory. A successful exploit could allow the attacker to retrieve sensitive information, including usernames, meeting information, or authentication tokens.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03116
CVE-2020-3347

Affected Products

Cisco Webex Meetings Desktop App