Lucene search

K
attackerkbAttackerKBAKB:50C24DDC-4812-44E4-81BD-EE1F707333F4
HistorySep 04, 2020 - 12:00 a.m.

CVE-2020-3495

2020-09-0400:00:00
attackerkb.com
13

0.007 Low

EPSS

Percentile

79.9%

Cisco Jabber is vulnerable to Cross Site Scripting (XSS) through XHTML-IM messages. The application does not properly sanitize incoming HTML messages and instead passes them through a flawed XSS filter.

Recent assessments:

wvu-r7 at September 03, 2020 7:38pm UTC reported:

This XSS combined with CVE-2020-3430, a protocol handler RCE vulnerability, is a potent combination.

Note that this attack requires intercepting/sending a crafted message to a recipient. It does not, however, require their interaction. If an attacker has local access to Jabber or is otherwise authenticated to a Jabber network, this isn’t a stretch.

Please patch this in your corporate networks! Attackers have been known to read IM messages and even send phishing links through them. This is worse, since it’s potentially wormable RCE… if you use Jabber at all. :–)

Tanisha48 at September 05, 2020 5:26pm UTC reported:

This XSS combined with CVE-2020-3430, a protocol handler RCE vulnerability, is a potent combination.

Note that this attack requires intercepting/sending a crafted message to a recipient. It does not, however, require their interaction. If an attacker has local access to Jabber or is otherwise authenticated to a Jabber network, this isn’t a stretch.

Please patch this in your corporate networks! Attackers have been known to read IM messages and even send phishing links through them. This is worse, since it’s potentially wormable RCE… if you use Jabber at all. :–)

Assessed Attacker Value: 4
Assessed Attacker Value: 4Assessed Attacker Value: 3

0.007 Low

EPSS

Percentile

79.9%

Related for AKB:50C24DDC-4812-44E4-81BD-EE1F707333F4