CVE Vulnerabilities

CVE-2021-1471

Improper Null Termination

Published: Mar 24, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

Weakness

The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.

Affected Software

NameVendorStart VersionEnd Version
JabberCisco*12.1.5 (excluding)
JabberCisco*12.8.7 (excluding)
JabberCisco*12.9.0 (including)
JabberCisco12.5.0 (including)12.5.4 (excluding)
JabberCisco12.6.0 (including)12.6.5 (excluding)
JabberCisco12.7.0 (including)12.7.4 (excluding)
JabberCisco12.8.0 (including)12.8.5 (excluding)
JabberCisco12.9.0 (including)12.9.5 (excluding)
JabberCisco12.9.0 (including)12.9.6 (excluding)

Potential Mitigations

References