PT-2017-1535 · Cisco · Cisco Webex Meetings Server
Publicado
2017-03-17
·
Atualizado
2017-07-12
·
CVE-2017-3880
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco WebEx Meetings Server versions 2.5 through 2.8
Description
The issue is related to insufficient authentication procedures in the software, potentially allowing a remote attacker to partially compromise the confidentiality and integrity of information. An unauthenticated, remote attacker could access limited meeting information on the Cisco WebEx Meetings Server.
Recommendations
For versions 2.5 through 2.8, apply the necessary patches or updates to resolve the authentication bypass issue, specifically considering the patch T29 orion merge and the Orion1.1.2.patch update.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Webex Meetings Server