QID 317244
Date Published: 2022-10-18
QID 317244: Cisco Jabber Client Software Extensible Messaging and Presence Protocol Stanza Smuggling Vulnerability (cisco-sa-jabber-xmpp-Ne9SCM)
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application.
Affected Products
Cisco Jabber for Windows, Cisco Jabber for MacOS.
NOTE: Cisco has confirmed that these vulnerabilities, with the exception of CVE-2022-20917, do not affect Cisco Jabber client software that is configured for either of the following modes: Phone-only mode or Team Messaging Mode.
QID Detection Logic (Authenticated):
This checks for vulnerable version of AnyConnect Mobility Client.
A successful exploit could allow the attacker to manipulate the content of XMPP messages, possibly allowing the attacker to cause the Jabber client application to perform unsafe actions.
Customers are advised to refer to cisco-sa-jabber-xmpp-Ne9SCM for more information.
- cisco-sa-jabber-xmpp-Ne9SCM -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-xmpp-Ne9SCM
CVEs related to QID 317244
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-jabber-xmpp-Ne9SCM |
|