CVE-2010-3270
Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted .atp file and then disconnecting from a meeting.
Does this matter?
Lower severity and a low EPSS score (4.18%). Track it; it rarely justifies an emergency change on its own.
Description
Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted .atp file and then disconnecting from a meeting. NOTE: since this is a site-specific issue with no expected action for consumers, it might be REJECTed.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:H/Au:M/C:C/I:C/A:C
- EPSS
- 4.18% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- cisco/webex meeting center
- Source
- cve@mitre.org
References
- http://securitytracker.com/id?1025015
- http://tools.cisco.com/security/center/viewAlert.x?alertId=22355
- http://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilities
- http://www.securityfocus.com/archive/1/516095/100/0/threaded
- http://www.securityfocus.com/bid/46078
- http://www.vupen.com/english/advisories/2011/0260Vendor Advisory
- http://securitytracker.com/id?1025015
- http://tools.cisco.com/security/center/viewAlert.x?alertId=22355
- http://www.coresecurity.com/content/webex-atp-and-wrf-overflow-vulnerabilities
- http://www.securityfocus.com/archive/1/516095/100/0/threaded
- http://www.securityfocus.com/bid/46078
- http://www.vupen.com/english/advisories/2011/0260Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.