PT-2021-3324 · Cisco · Cisco Jabber For Mac+2
Rob Vinson
+1
·
Published
2021-06-16
·
Updated
2021-06-24
·
CVE-2021-1570
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Jabber for Windows (affected versions not specified)
Cisco Jabber for Mac (affected versions not specified)
Cisco Jabber for mobile platforms (affected versions not specified)
Description
The issue is related to errors in resource management in the Cisco Jabber software platform. An attacker could exploit this to cause a denial of service (DoS) condition by sending a specially crafted XMPP message. This could allow an attacker to access sensitive information or disrupt service.
Recommendations
For Cisco Jabber for Windows, consider restricting access to the XMPP protocol until a fix is available.
For Cisco Jabber for Mac, avoid using the software for sensitive operations until the issue is resolved.
For Cisco Jabber for mobile platforms, as a temporary workaround, consider disabling the XMPP messaging functionality until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Jabber For Mac
Cisco Jabber For Windows
Cisco Jabber For Mobile Platforms