Cisco Webex App
cpe:2.3:a:cisco:webex_app:*:*:*:*:web:*:*
- 44.6
- 44.7
A remote code execution vulnerability has been identified in Cisco Webex App, stemming from inadequate input validation in the custom URL parser. This issue allows an unauthenticated, remote attacker to convince a user to download arbitrary files, which could then be used to execute commands on the user's host. The vulnerability arises when the application processes a crafted meeting invite link.
Exploitation of this vulnerability could lead to unauthorized remote code execution on the affected user's device, with the executed commands running under the user's privileges.
Cisco has released software updates to address this vulnerability. Users can obtain these updates through their usual channels. For specific upgrade instructions, refer to the Cisco Security Vulnerability Policy.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.