9.9

CVE-2021-1411

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoJabber SwPlatformwindows Version < 12.1.5
CiscoJabber SwPlatformwindows Version >= 12.5.0 < 12.5.4
CiscoJabber SwPlatformwindows Version >= 12.6.0 < 12.6.5
CiscoJabber SwPlatformwindows Version >= 12.7.0 < 12.7.4
CiscoJabber SwPlatformwindows Version >= 12.8.0 < 12.8.5
CiscoJabber SwPlatformwindows Version >= 12.9.0 < 12.9.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.623
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
psirt@cisco.com 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-170 Improper Null Termination

The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.