A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Cisco Webex Meetings Server site. If successful, the attacker could gain the privileges of another user within the affected Webex site.
2020-06-18T03:15:14.497
2024-11-21T05:30:52.717
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | webex_meetings | ≤ 39.5.25 | Yes |
Application | cisco | webex_meetings | ≤ 40.4.10 | Yes |
Application | cisco | webex_meetings | 40.6.0 | Yes |
Application | cisco | webex_meetings_server | < 4.0 | Yes |
Application | cisco | webex_meetings_server | 4.0 | Yes |
Application | cisco | webex_meetings_server | 4.0 | Yes |
Application | cisco | webex_meetings_server | 4.0 | Yes |
Application | cisco | webex_meetings_server | 4.0 | Yes |