ID

VAR-201707-0956


CVE

CVE-2017-6753


TITLE

plural Cisco WebEx Product buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-006452

DESCRIPTION

A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center), and Cisco WebEx Meetings when they are running on Microsoft Windows. The vulnerability is due to a design defect in the extension. An attacker who can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser. The following versions of the Cisco WebEx browser extensions are affected: Versions prior to 1.0.12 of the Cisco WebEx extension on Google Chrome, Versions prior to 1.0.12 of the Cisco WebEx extension on Mozilla Firefox. Cisco Bug IDs: CSCvf15012 CSCvf15020 CSCvf15030 CSCvf15033 CSCvf15036 CSCvf15037. plural Cisco WebEx The product contains a buffer error vulnerability. Vendors have confirmed this vulnerability Bug ID CSCvf15012 , CSCvf15020 , CSCvf15030 , CSCvf15033 , CSCvf15036 ,and CSCvf15037 It is released as.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Google Chrome for Windows is a Windows-based web browser developed by Google (Google). Mozilla Firefox for Windows is an open source web browser based on the Windows platform from the Mozilla Foundation of the United States

Trust: 1.98

sources: NVD: CVE-2017-6753 // JVNDB: JVNDB-2017-006452 // BID: 99614 // VULHUB: VHN-114956

AFFECTED PRODUCTS

vendor:ciscomodel:webex meetingsscope:eqversion:t30_base

Trust: 1.6

vendor:ciscomodel:webex meetings server 2.5 mr6 patchscope:eqversion:1

Trust: 1.6

vendor:ciscomodel:webex meetings serverscope:eqversion:2.6.1.39

Trust: 1.6

vendor:ciscomodel:webex event centerscope:eqversion:t31_base

Trust: 1.6

vendor:ciscomodel:webex meetings serverscope:eqversion:2.5.1.29

Trust: 1.6

vendor:ciscomodel:webex meetings server 2.5scope:eqversion:mr1

Trust: 1.6

vendor:ciscomodel:webex meetings server 2.7 mr1 patchscope:eqversion:1

Trust: 1.6

vendor:ciscomodel:webex meetings server 2.0 mr9 patchscope:eqversion:1

Trust: 1.6

vendor:ciscomodel:webex meetings server 2.5scope:eqversion:mr5

Trust: 1.6

vendor:ciscomodel:webex meetings serverscope:eqversion:2.8_base

Trust: 1.6

vendor:ciscomodel:webex meetings serverscope:eqversion:2.5.99.2

Trust: 1.0

vendor:ciscomodel:webex meeting centerscope:eqversion:t31_base

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:1.5_base

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.7 mr2 patchscope:eqversion:1

Trust: 1.0

vendor:ciscomodel:webex training centerscope:eqversion:t31_base

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0 mr9 patchscope:eqversion:3

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0scope:eqversion:mr9

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.5 mr2 patchscope:eqversion:1

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0scope:eqversion:mr5

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:2.0.1.107

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:2.0_base

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:2.7.1

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:2.7_base

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.6scope:eqversion:mr2

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0scope:eqversion:mr8

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:1.5.1.6

Trust: 1.0

vendor:ciscomodel:webex meeting centerscope:eqversion:t30_base

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:2.5.1.5

Trust: 1.0

vendor:ciscomodel:webex training centerscope:eqversion:t30_base

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:1.1_base

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.6scope:eqversion:mr1

Trust: 1.0

vendor:ciscomodel:webex meeting centerscope:eqversion:t32_base

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.6 mr1 patchscope:eqversion:1

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.6 mr3 patchscope:eqversion:1

Trust: 1.0

vendor:ciscomodel:webex training centerscope:eqversion:t32_base

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0 mr8 patchscope:eqversion:1

Trust: 1.0

vendor:ciscomodel:webex support centerscope:eqversion:t31_base

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.6 mr3 patchscope:eqversion:2

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0 mr9 patchscope:eqversion:2

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.5 mr6 patchscope:eqversion:3

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0scope:eqversion:mr6

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:2.5_base

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0scope:eqversion:mr2

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0scope:eqversion:mr7

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.5scope:eqversion:mr2

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.6scope:eqversion:mr3

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.7scope:eqversion:mr1

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.5scope:eqversion:mr6

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.6 mr2 patchscope:eqversion:1

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0scope:eqversion:mr4

Trust: 1.0

vendor:ciscomodel:webex support centerscope:eqversion:t30_base

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.5 mr6 patchscope:eqversion:4

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.5scope:eqversion:mr4

Trust: 1.0

vendor:ciscomodel:webex event centerscope:eqversion:t30_base

Trust: 1.0

vendor:ciscomodel:webex event centerscope:eqversion:t32_base

Trust: 1.0

vendor:ciscomodel:webex support centerscope:eqversion:t32_base

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.5 mr6 patchscope:eqversion:2

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.0scope:eqversion:mr3

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:2.6.0

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.5 mr5 patchscope:eqversion:1

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.7scope:eqversion:mr2

Trust: 1.0

vendor:ciscomodel:webex meetings server 2.5scope:eqversion:mr3

Trust: 1.0

vendor:ciscomodel:webex meetings serverscope:eqversion:1.5.1.131

Trust: 1.0

vendor:ciscomodel:webex event centerscope: - version: -

Trust: 0.8

vendor:ciscomodel:webex meeting centerscope: - version: -

Trust: 0.8

vendor:ciscomodel:webex meetingsscope: - version: -

Trust: 0.8

vendor:ciscomodel:webex meetings serverscope: - version: -

Trust: 0.8

vendor:ciscomodel:webex support centerscope: - version: -

Trust: 0.8

vendor:ciscomodel:webex training centerscope: - version: -

Trust: 0.8

vendor:ciscomodel:webex meetings server t29 orion mergescope: - version: -

Trust: 0.3

vendor:ciscomodel:webex meetings serverscope:eqversion:2.8

Trust: 0.3

vendor:ciscomodel:webex meetings serverscope:eqversion:2.7

Trust: 0.3

vendor:ciscomodel:webex meetings t32scope: - version: -

Trust: 0.3

vendor:ciscomodel:webex meetings t31scope: - version: -

Trust: 0.3

vendor:ciscomodel:webex meetings t30scope: - version: -

Trust: 0.3

vendor:ciscomodel:webex meetings t29scope: - version: -

Trust: 0.3

vendor:ciscomodel:webex extensionscope:eqversion:1.0.9

Trust: 0.3

vendor:ciscomodel:webex extensionscope:eqversion:1.0.5

Trust: 0.3

vendor:ciscomodel:webex extensionscope:eqversion:1.0.3

Trust: 0.3

vendor:ciscomodel:webex extensionscope:eqversion:1.0.2

Trust: 0.3

vendor:ciscomodel:webex extensionscope:neversion:1.0.12

Trust: 0.3

sources: BID: 99614 // JVNDB: JVNDB-2017-006452 // CNNVD: CNNVD-201707-864 // NVD: CVE-2017-6753

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-6753
value: HIGH

Trust: 1.0

NVD: CVE-2017-6753
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201707-864
value: HIGH

Trust: 0.6

VULHUB: VHN-114956
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-6753
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-114956
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-6753
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-114956 // JVNDB: JVNDB-2017-006452 // CNNVD: CNNVD-201707-864 // NVD: CVE-2017-6753

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-114956 // JVNDB: JVNDB-2017-006452 // NVD: CVE-2017-6753

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201707-864

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201707-864

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-006452

PATCH

title:cisco-sa-20170717-webexurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170717-webex

Trust: 0.8

title:Google Chrome and Mozilla firefox for Windows Cisco WebEx Browser Extension Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=71852

Trust: 0.6

sources: JVNDB: JVNDB-2017-006452 // CNNVD: CNNVD-201707-864

EXTERNAL IDS

db:NVDid:CVE-2017-6753

Trust: 2.8

db:BIDid:99614

Trust: 2.0

db:SECTRACKid:1038911

Trust: 1.7

db:SECTRACKid:1038910

Trust: 1.7

db:SECTRACKid:1038909

Trust: 1.7

db:JVNDBid:JVNDB-2017-006452

Trust: 0.8

db:CNNVDid:CNNVD-201707-864

Trust: 0.7

db:VULHUBid:VHN-114956

Trust: 0.1

sources: VULHUB: VHN-114956 // BID: 99614 // JVNDB: JVNDB-2017-006452 // CNNVD: CNNVD-201707-864 // NVD: CVE-2017-6753

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20170717-webex

Trust: 2.0

url:http://www.securityfocus.com/bid/99614

Trust: 1.7

url:http://www.securitytracker.com/id/1038909

Trust: 1.7

url:http://www.securitytracker.com/id/1038910

Trust: 1.7

url:http://www.securitytracker.com/id/1038911

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-6753

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-6753

Trust: 0.8

url:https://bugs.chromium.org/p/project-zero/issues/detail?id=1324&can=1&q=&sort=-id&colspec=id%20status%20owner%20summary%20modified%20cve&desc=2

Trust: 0.3

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-114956 // BID: 99614 // JVNDB: JVNDB-2017-006452 // CNNVD: CNNVD-201707-864 // NVD: CVE-2017-6753

CREDITS

Tavis Ormandy of Google Project Zero and Cris Neckar of Divergent Security.

Trust: 0.9

sources: BID: 99614 // CNNVD: CNNVD-201707-864

SOURCES

db:VULHUBid:VHN-114956
db:BIDid:99614
db:JVNDBid:JVNDB-2017-006452
db:CNNVDid:CNNVD-201707-864
db:NVDid:CVE-2017-6753

LAST UPDATE DATE

2024-11-23T23:12:25.355000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-114956date:2019-10-09T00:00:00
db:BIDid:99614date:2017-07-17T00:00:00
db:JVNDBid:JVNDB-2017-006452date:2017-08-25T00:00:00
db:CNNVDid:CNNVD-201707-864date:2019-10-17T00:00:00
db:NVDid:CVE-2017-6753date:2024-11-21T03:30:27.107

SOURCES RELEASE DATE

db:VULHUBid:VHN-114956date:2017-07-25T00:00:00
db:BIDid:99614date:2017-07-17T00:00:00
db:JVNDBid:JVNDB-2017-006452date:2017-08-25T00:00:00
db:CNNVDid:CNNVD-201707-864date:2017-07-19T00:00:00
db:NVDid:CVE-2017-6753date:2017-07-25T19:29:00.397