VulnerabilityModified
CVE-2014-0666
Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug…
MEDIUM 4.3EPSS 5.54%
Does this matter?
Lower severity and a low EPSS score (5.54%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug ID CSCug48056.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 5.54% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- cisco/jabber
- Source
- psirt@cisco.com
References
- http://osvdb.org/102122
- http://secunia.com/advisories/56331
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0666Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32451Vendor Advisory
- http://www.securityfocus.com/bid/64965Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029635Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90435
- http://osvdb.org/102122
- http://secunia.com/advisories/56331
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0666Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32451Vendor Advisory
- http://www.securityfocus.com/bid/64965Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029635Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90435
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.