VDB
CVE-2020-3495
CVE-2020-3495
PUBLISHED
CVSS 9.899999618530273 CRITICAL
A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages to the affected software. A successful exploit could allow the attacker to cause the application to execute arbitrary programs on the targeted system with the privileges of the user account that is running the Cisco Jabber client software, possibly resulting in arbitrary code execution.
EPSS 4.40% · 89.2th percentile
Risk Scores
CVSS 3.1
9.899999618530273
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
4.40%
89.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Jabber | n/a |
| cisco | jabber | 12.6, 12.9, 12.1 |
Exploit Intelligence
- 20200902 Cisco Jabber for Windows Message Handling Arbitrary Code Execution Vulnerability (circl)
- ET EXPLOIT Possible Cisco Jabber RCE Inbound (CVE-2020-3495) (emergingthreats)
- ET EXPLOIT Possible Cisco Jabber RCE Inbound (CVE-2020-3495) (emergingthreats)
- ET EXPLOIT Possible Cisco Jabber RCE Inbound (CVE-2020-3495) (emergingthreats)
Timeline
- Sep 2, 2020 CVE Published
- Sep 5, 2020 PoC Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-UyTKCPGg advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-cli-privescl-sDVEmhqv advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-LJtNFjeN advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-vY8M4KGB advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-file-overwrite-UONzPMkr advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-3495 advisory