Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-20255


A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join service. This vulnerability is due to improper handling of malicious HTTP requests to the affected service. An attacker could exploit this vulnerability by manipulating stored HTTP responses within the service, also known as HTTP cache poisoning. A successful exploit could allow the attacker to cause the Webex Meetings service to return incorrect HTTP responses to clients.


Published

2025-05-21T17:15:56.890

Last Modified

2025-07-14T20:34:07.507

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-349

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco webex_meetings - Yes

References