SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-33672

Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message.

CRITICAL 9.6EPSS 1.10%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Due to missing encoding in SAP Contact Center's Communication Desktop component- version 700, an attacker could send malicious script in chat message. When the message is accepted by the chat recipient, the script gets executed in their scope. Due to the usage of ActiveX in the application, the attacker can further execute operating system level commands in the chat recipient's scope. This could lead to a complete compromise of their confidentiality, integrity, and could temporarily impact their availability.

CVSS 3.1
9.6 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS
1.10% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-116
Affected
sap/contact center
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.