PT-2013-4382 · Cisco · Cisco Webex
Publicado
2013-07-31
·
Atualizado
2017-08-29
·
CVE-2013-3425
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco WebEx version 11
Description
The issue allows remote authenticated users to enumerate files by analyzing different error messages generated for invalid file-access attempts. This is possible due to the Meeting Center component in Cisco WebEx generating distinct error messages based on whether a file exists.
Recommendations
For Cisco WebEx version 11, consider restricting access to the Meeting Center component until a fix is available. As a temporary workaround, limit the ability of remote authenticated users to make file-access attempts to minimize the risk of file enumeration.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Webex