← Back

CVE-2024-20396

nvd nist
Published: Jul 17, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability exists because the affected application does not safely handle file protocol handlers. An attacker could exploit this vulnerability by persuading a user to follow a link that is designed to cause the application to send requests. If the attacker can observe transmitted traffic in a privileged network position, a successful exploit could allow the attacker to capture sensitive information, including credential information, from the requests.

Affected (44)

Products: Cisco: Webex Teams
1 product
Webex Teams
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 3.0.13464.0
Version 3.0.13538.0
Version 3.0.13588.0
Version 3.0.14154.0
Version 3.0.14234.0
Version 3.0.14375.0
Version 3.0.14741.0
Version 3.0.14866.0
Version 3.0.15015.0
Version 3.0.15036.0
Version 3.0.15092.0
Version 3.0.15131.0
Version 3.0.15164.0
Version 3.0.15221.0
Version 3.0.15333.0
Version 3.0.15410.0
Version 3.0.15485.0
Version 3.0.15645.0
Version 3.0.15711.0
Version 3.0.16040.0
Version 3.0.16269.0
Version 3.0.16273.0
Version 3.0.16285.0
Version 42.1.0.21190
Version 42.10.0.23814
Version 42.11.0.24187
Version 42.12.0.24485
Version 42.2.0.21338
Version 42.2.0.21486
Version 42.3.0.21576
Version 42.4.1.22032
Version 42.5.0.22259
Version 42.6.0.22565
Version 42.6.0.22645
Version 42.7.0.22904
Version 42.7.0.23054
Version 42.8.0.23214
Version 42.8.0.23281
Version 42.9.0.23494
Version 43.1.0.24716
Version 43.2.0.25157
Version 43.2.0.25211
Version 43.3.0.25468
Version 43.4.0.25788

Timeline

No history available yet.