CVE-2020-3182 MEDIUM

CVE-2020-3182: Cisco Webex Meetings Client for MacOS Information Disclosure Vulnerability

Vendor Cisco
Product Cisco Webex Meetings
Weakness CWE-200 · Info exposure
Published March 4, 2020
Last update November 15, 2024

CVSS base score

4.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnerability exists because sensitive information is included in the mDNS reply. An attacker could exploit this vulnerability by doing an mDNS query for a particular service against an affected device. A successful exploit could allow the attacker to gain access to sensitive information.

Key dates

02Disclosure timeline

March 4, 2020 CVE published
November 15, 2024 Record updated