Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2020-3194— Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerability

Quick assessment

Affected
Cisco Cisco Webex Meetings
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco Webex Network Webex Player是美国思科(Cisco)公司的一款用于播放视频会议记录的播放器。 Cisco Webex Network Recording Player和Webex Player中存在输入验证错误漏洞。攻击者可通过诱使用户使用受影响的软件打开恶意的ARF或WRF文件利用该漏洞以目标用户权限在受影响系统上执行任意代码。

AI Predicted 8.8 Difficulty: Easy EPSS 1.91% · P78
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-3194

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
内存缓冲区边界内操作的限制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Cisco Webex Network Webex Player 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Webex Network Webex Player是美国思科(Cisco)公司的一款用于播放视频会议记录的播放器。 Cisco Webex Network Recording Player和Webex Player中存在输入验证错误漏洞。攻击者可通过诱使用户使用受影响的软件打开恶意的ARF或WRF文件利用该漏洞以目标用户权限在受影响系统上执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cisco Cisco Webex Meetings n/a -

II. Public POCs for CVE-2020-3194

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-3194

登录查看更多情报信息。

Vendor Advisories for CVE-2020-3194 (1)

Same Patch Batch · Cisco · 2020-04-15 · 17 CVEs total

CVE-2020-3161 Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
CVE-2020-3162 Cisco IoT Field Network Director Denial of Service Vulnerability
CVE-2020-3177 Cisco Unified Communications Manager Path Traversal Vulnerability
CVE-2020-3239 Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
CVE-2020-3240 Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
CVE-2020-3243 Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
CVE-2020-3247 Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
CVE-2020-3248 Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
CVE-2020-3249 Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
CVE-2020-3250 Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
CVE-2020-3251 Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
CVE-2020-3252 Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
CVE-2020-3260 Cisco Aironet Series Access Points Client Packet Processing Denial of Service Vulnerabilit
CVE-2020-3261 Cisco Mobility Express Software Cross-Site Request Forgery Vulnerability
CVE-2020-3262 Cisco Wireless LAN Controller CAPWAP Denial of Service Vulnerability
CVE-2020-3273 Cisco Wireless LAN Controller 802.11 Generic Advertisement Service Denial of Service Vulne

IV. Related Vulnerabilities

V. Comments for CVE-2020-3194

No comments yet


Leave a comment