Kaspersky ID:
KLA12059
Date de la détection:
12/10/2020
Mis à jour:
01/25/2024

Description

Multiple vulnerabilities were found in Cisco Jabber. Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. A command injection vulnerability in Cisco Jabber can be exploited remotely to execute arbitrary code.
  2. An unauthorized access vulnerability in Cisco Jabber can be exploited remotely to obtain sensitive information and bypass security restrictions.
  3. An information disclosure vulnerability in Cisco Jabber can be exploited remotely via special crafted message to obtain sensitive information.
  4. A program execution vulnerability in Cisco Jabber can be exploited remotely via special crafted XMPP message to execute arbitrary code.
  5. A script injection vulnerability in Cisco Jabber can be exploited remotely via special crafted XMPP message to execute arbitrary code.

Fiches de renseignement originales

Exploitation

Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.

Produits associés

Liste CVE

  • CVE-2020-27133
    critical
  • CVE-2020-27127
    critical
  • CVE-2020-27132
    critical
  • CVE-2020-26085
    critical
  • CVE-2020-27134
    critical

En savoir plus

Découvrez les statistiques de la propagation des vulnérabilités dans votre région statistics.securelist.com

Vous avez trouvé une inexactitude dans la description de cette vulnérabilité ? Faites-le nous savoir !
Kaspersky IT Security Calculator:
Calculez le profil de sécurité de votre entreprise
Apprendre encore plus
Kaspersky!
Votre vie en ligne mérite une protection complète!
Apprendre encore plus
Do you want to save your changes?
Your message has been sent successfully.