PT-2017-1535 · Cisco · Cisco Webex Meetings Server

Publicado

2017-03-17

·

Atualizado

2017-07-12

·

CVE-2017-3880

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco WebEx Meetings Server versions 2.5 through 2.8
Description The issue is related to insufficient authentication procedures in the software, potentially allowing a remote attacker to partially compromise the confidentiality and integrity of information. An unauthenticated, remote attacker could access limited meeting information on the Cisco WebEx Meetings Server.
Recommendations For versions 2.5 through 2.8, apply the necessary patches or updates to resolve the authentication bypass issue, specifically considering the patch T29 orion merge and the Orion1.1.2.patch update.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-00680
CVE-2017-3880

Produtos afetados

Cisco Webex Meetings Server