PT-2013-4382 · Cisco · Cisco Webex
Published
2013-07-31
·
Updated
2017-08-29
·
CVE-2013-3425
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco WebEx version 11
Description
The issue allows remote authenticated users to enumerate files by analyzing different error messages generated for invalid file-access attempts. This is possible due to the Meeting Center component in Cisco WebEx generating distinct error messages based on whether a file exists.
Recommendations
For Cisco WebEx version 11, consider restricting access to the Meeting Center component until a fix is available. As a temporary workaround, limit the ability of remote authenticated users to make file-access attempts to minimize the risk of file enumeration.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Webex