
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2022-20863) was discovered in the messaging interface of Cisco Webex App (formerly Webex Teams). The vulnerability was first published on September 7, 2022, and affects versions of Cisco Webex App prior to 42.7. This security flaw received a CVSS base score of 4.3 (Medium) and was identified with CWE-450 (Multiple Interpretations of UI Input) (Cisco Advisory, NVD).
The vulnerability exists due to improper handling of character rendering in the messaging interface. It received a CVSS v3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N, indicating that it can be exploited remotely with low attack complexity, requires no privileges but does require user interaction, and can result in low impact to integrity (Cisco Advisory).
A successful exploitation of this vulnerability could allow an attacker to modify the display of links or other content within the interface, potentially enabling phishing or spoofing attacks. The vulnerability affects the integrity of displayed content but does not impact confidentiality or availability (Cisco Advisory).
The vulnerability can be exploited by an unauthenticated, remote attacker by sending specially crafted messages within the application interface. As of the advisory publication, Cisco PSIRT was not aware of any public announcements or malicious use of this vulnerability (Cisco Advisory).
Cisco has released software updates that address this vulnerability in version 42.7 and later. There are no workarounds available for this vulnerability. Users running versions earlier than 42.7 are advised to migrate to a fixed release (Cisco Advisory).
The vulnerability was discovered and reported by Rex, Bruce, and Zachary from Binance Red Team, demonstrating collaboration between security researchers and vendors in responsible vulnerability disclosure (Cisco Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."