9.3
CVE-2017-6753
- EPSS 11.1%
- Veröffentlicht 25.07.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center), and Cisco WebEx Meetings when they are running on Microsoft Windows. The vulnerability is due to a design defect in the extension. An attacker who can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser. The following versions of the Cisco WebEx browser extensions are affected: Versions prior to 1.0.12 of the Cisco WebEx extension on Google Chrome, Versions prior to 1.0.12 of the Cisco WebEx extension on Mozilla Firefox. Cisco Bug IDs: CSCvf15012 CSCvf15020 CSCvf15030 CSCvf15033 CSCvf15036 CSCvf15037.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Webex Event Center Versiont30_base
Cisco ≫ Webex Event Center Versiont31_base
Cisco ≫ Webex Event Center Versiont32_base
Cisco ≫ Webex Meeting Center Versiont30_base
Cisco ≫ Webex Meeting Center Versiont31_base
Cisco ≫ Webex Meeting Center Versiont32_base
Cisco ≫ Webex Meetings Versiont30_base
Cisco ≫ Webex Meetings Server Version1.1_base
Cisco ≫ Webex Meetings Server Version1.5.1.6
Cisco ≫ Webex Meetings Server Version1.5.1.131
Cisco ≫ Webex Meetings Server Version1.5_base
Cisco ≫ Webex Meetings Server Version2.0.1.107
Cisco ≫ Webex Meetings Server Version2.0_base
Cisco ≫ Webex Meetings Server Version2.5.1.5
Cisco ≫ Webex Meetings Server Version2.5.1.29
Cisco ≫ Webex Meetings Server Version2.5.99.2
Cisco ≫ Webex Meetings Server Version2.5_base
Cisco ≫ Webex Meetings Server Version2.6.0
Cisco ≫ Webex Meetings Server Version2.6.1.39
Cisco ≫ Webex Meetings Server Version2.7.1
Cisco ≫ Webex Meetings Server Version2.7_base
Cisco ≫ Webex Meetings Server Version2.8_base
Cisco ≫ Webex Meetings Server 2.0 Versionmr2
Cisco ≫ Webex Meetings Server 2.0 Versionmr3
Cisco ≫ Webex Meetings Server 2.0 Versionmr4
Cisco ≫ Webex Meetings Server 2.0 Versionmr5
Cisco ≫ Webex Meetings Server 2.0 Versionmr6
Cisco ≫ Webex Meetings Server 2.0 Versionmr7
Cisco ≫ Webex Meetings Server 2.0 Versionmr8
Cisco ≫ Webex Meetings Server 2.0 Versionmr9
Cisco ≫ Webex Meetings Server 2.0 Mr8 Patch Version1
Cisco ≫ Webex Meetings Server 2.0 Mr9 Patch Version1
Cisco ≫ Webex Meetings Server 2.0 Mr9 Patch Version2
Cisco ≫ Webex Meetings Server 2.0 Mr9 Patch Version3
Cisco ≫ Webex Meetings Server 2.5 Versionmr1
Cisco ≫ Webex Meetings Server 2.5 Versionmr2
Cisco ≫ Webex Meetings Server 2.5 Versionmr3
Cisco ≫ Webex Meetings Server 2.5 Versionmr4
Cisco ≫ Webex Meetings Server 2.5 Versionmr5
Cisco ≫ Webex Meetings Server 2.5 Versionmr6
Cisco ≫ Webex Meetings Server 2.5 Mr2 Patch Version1
Cisco ≫ Webex Meetings Server 2.5 Mr5 Patch Version1
Cisco ≫ Webex Meetings Server 2.5 Mr6 Patch Version1
Cisco ≫ Webex Meetings Server 2.5 Mr6 Patch Version2
Cisco ≫ Webex Meetings Server 2.5 Mr6 Patch Version3
Cisco ≫ Webex Meetings Server 2.5 Mr6 Patch Version4
Cisco ≫ Webex Meetings Server 2.6 Versionmr1
Cisco ≫ Webex Meetings Server 2.6 Versionmr2
Cisco ≫ Webex Meetings Server 2.6 Versionmr3
Cisco ≫ Webex Meetings Server 2.6 Mr1 Patch Version1
Cisco ≫ Webex Meetings Server 2.6 Mr2 Patch Version1
Cisco ≫ Webex Meetings Server 2.6 Mr3 Patch Version1
Cisco ≫ Webex Meetings Server 2.6 Mr3 Patch Version2
Cisco ≫ Webex Meetings Server 2.7 Versionmr1
Cisco ≫ Webex Meetings Server 2.7 Versionmr2
Cisco ≫ Webex Meetings Server 2.7 Mr1 Patch Version1
Cisco ≫ Webex Meetings Server 2.7 Mr2 Patch Version1
Cisco ≫ Webex Support Center Versiont30_base
Cisco ≫ Webex Support Center Versiont31_base
Cisco ≫ Webex Support Center Versiont32_base
Cisco ≫ Webex Training Center Versiont30_base
Cisco ≫ Webex Training Center Versiont31_base
Cisco ≫ Webex Training Center Versiont32_base
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 11.1% | 0.932 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.