SB2021061718 - Multiple vulnerabilities in Cisco Jabber Desktop and Mobile Client



SB2021061718 - Multiple vulnerabilities in Cisco Jabber Desktop and Mobile Client

Published: June 17, 2021

Security Bulletin ID SB2021061718
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Insufficiently protected credentials (CVE-ID: CVE-2021-1569)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack or gain access to sensitive information.

The vulnerability exists due to improper input validation when processing messages. A remote authenticated attacker can send a specially crafted Extensible Messaging and Presence Protocol (XMPP) message to the affected application and gain access to return sensitive authentication information to another system, which the attacker could use in further attacks.


2) Resource management error (CVE-ID: CVE-2021-1570)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation of message content. A remote authenticated attacker can send  specially crafted message to the application and perform a denial of service (DoS) attack.


Remediation

Install update from vendor's website.