CVE-2021-1242CWE-450

Cisco Webex Teams Shared File Manipulation Vulnerability

Medium · published January 13, 2021

CVSS v3.1
4.3
EPSS
1%
Percentile
69.7
In the wild
Unconfirmed
What it is

A vulnerability in Cisco Webex Teams could allow an unauthenticated, remote attacker to manipulate file names within the messaging interface. The vulnerability exists because the affected software mishandles character rendering. An attacker could exploit this vulnerability by sharing a file within the application interface. A successful exploit could allow the attacker to modify how the shared file name displays within the interface, which could allow the attacker to conduct phishing or spoofing attacks.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.01352 · 69.7th percentile
Weakness
CWE-450 · Multiple Interpretations of UI Input
Published
2021-01-13T21:17Z
EPSS history
Timeline
  • 13 JAN 21:17Z
    Cisco Webex Teams Shared File Manipulation Vulnerability
    cvelistv5