CVE-2024-20395 is a high-severity vulnerability in the media retrieval functionality of Cisco Webex App that could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. The vulnerability, rated 7.3 HIGH on CVSS, stems from insecure transmission of requests for embedded media, enabling an attacker in a privileged network position to capture and potentially reuse session tokens. While the exploit requires user interaction (UI:R), there is currently no public exploit code available, nor is it listed on the KEV catalog, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.13464.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_teams:3.0.13464.0:*:*:*:*:-:*:* | ||
3.0.13538.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_teams:3.0.13538.0:*:*:*:*:-:*:* | ||
3.0.13588.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_teams:3.0.13588.0:*:*:*:*:-:*:* | ||
3.0.14154.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_teams:3.0.14154.0:*:*:*:*:-:*:* | ||
3.0.14234.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_teams:3.0.14234.0:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.