Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2020-3321

A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to cause the Webex player application to crash when trying to view the malicious file.

  • Published: Jun 3, 2020
  • Updated: Apr 14, 2023
  • CVE: CVE-2020-3321
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 3.3
  • AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
cisco / webex_player - 3.0
cisco / webex_player 3.0 3.0.x
cisco / webex_player 3.0-maintenance_release1 3.0-maintenance_release1.x
cisco / webex_player 3.0-maintenance_release2 3.0-maintenance_release2.x
cisco / webex_player 4.0 4.0.x
cisco / webex_player 4.0-maintenance_release1 4.0-maintenance_release1.x
cisco / webex_player 4.0-maintenance_release2 4.0-maintenance_release2.x
cisco / webex_network_recording_player - 3.0
cisco / webex_network_recording_player 3.0 3.0.x
cisco / webex_network_recording_player 3.0-maintenance_release1 3.0-maintenance_release1.x
cisco / webex_network_recording_player 3.0-maintenance_release2 3.0-maintenance_release2.x
cisco / webex_network_recording_player 4.0 4.0.x
cisco / webex_network_recording_player 4.0-maintenance_release1 4.0-maintenance_release1.x
cisco / webex_network_recording_player 4.0-maintenance_release2 4.0-maintenance_release2.x