CVE-2019-12645 (CNNVD-201909-157)
中文标题:
Cisco Jabber Client Framework 输入验证错误漏洞
英文标题:
Cisco Jabber Client Framework for Mac Code Execution Vulnerability
漏洞描述
中文描述:
Cisco Jabber Client Framework(JCF)是美国思科(Cisco)公司的一套统一通信客户端框架。该框架提供了在线状态显示、即时消息、语音等功能。 基于Mac平台的Cisco JCF 12.6(1)及之前版本中存在输入验证错误漏洞,该漏洞源于程序为文件分配了不正确的权限。本地攻击者可利用该漏洞执行任意代码或修改设备上的配置文件。
英文描述:
A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to execute arbitrary code on an affected device The vulnerability is due to improper file level permissions on an affected device when it is running Cisco JCF for Mac Software. An attacker could exploit this vulnerability by authenticating to the affected device and executing arbitrary code or potentially modifying certain configuration files. A successful exploit could allow the attacker to execute arbitrary code or modify certain configuration files on the device using the privileges of the installed Cisco JCF for Mac Software.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Jabber for Mac | - | < 12.6(1) | - |
cpe:2.3:a:cisco:cisco_jabber_for_mac:*:*:*:*:*:*:*:*
|
| cisco | jabber | * | - | - |
cpe:2.3:a:cisco:jabber:*:*:*:*:*:macos:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2019-12645 |
2025-11-11 15:20:00 | 2025-11-11 07:35:30 |
| NVD | nvd_CVE-2019-12645 |
2025-11-11 14:56:26 | 2025-11-11 07:44:03 |
| CNNVD | cnnvd_CNNVD-201909-157 |
2025-11-11 15:10:16 | 2025-11-11 07:54:57 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 输入验证错误
- cnnvd_id: 未提取 -> CNNVD-201909-157
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 2
- data_sources: ['cve'] -> ['cve', 'nvd']