Lucene search

K
ciscoCiscoCISCO-SA-20171129-WEBEX1
HistoryNov 29, 2017 - 4:00 p.m.

Cisco WebEx Network Recording Player Denial of Service Vulnerability

2017-11-2916:00:00
tools.cisco.com
16

EPSS

0.001

Percentile

37.5%

A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by providing a user with a malicious WRF file via email or URL and convincing the user to open the file. A successful exploit could cause an affected player to crash, resulting in a DoS condition.

Cisco WebEx players are applications that are used to play back WebEx meeting recordings that have been recorded by an online meeting attendee. The player can be automatically installed when the user accesses a recording file that is hosted on a WebEx server.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-webex1 [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-webex1”]

Affected configurations

Vulners
Node
ciscowebex_wrf_player_t29Matchany
OR
ciscowebex_meetingsMatchany
OR
ciscowebex_wrf_player_t29Matchany
OR
ciscowebex_meetingsMatchany
VendorProductVersionCPE
ciscowebex_wrf_player_t29anycpe:2.3:a:cisco:webex_wrf_player_t29:any:*:*:*:*:*:*:*
ciscowebex_meetingsanycpe:2.3:a:cisco:webex_meetings:any:*:*:*:*:*:*:*

EPSS

0.001

Percentile

37.5%

Related for CISCO-SA-20171129-WEBEX1