PT-2021-1762 · Cisco · Cisco Webex Teams

Hou Jingyi

·

Published

2021-01-13

·

Updated

2021-01-20

·

CVE-2021-1242

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Webex Teams (affected versions not specified)
Description: A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface. The issue exists due to the software's mishandling of character rendering. An attacker could exploit this by sharing a file within the application interface, potentially allowing them to modify how the shared file name displays. This could enable the attacker to conduct phishing or spoofing attacks.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00462
CVE-2021-1242

Affected Products

Cisco Webex Teams