PT-2013-4382 · Cisco · Cisco Webex

Published

2013-07-31

·

Updated

2017-08-29

·

CVE-2013-3425

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco WebEx version 11
Description The issue allows remote authenticated users to enumerate files by analyzing different error messages generated for invalid file-access attempts. This is possible due to the Meeting Center component in Cisco WebEx generating distinct error messages based on whether a file exists.
Recommendations For Cisco WebEx version 11, consider restricting access to the Meeting Center component until a fix is available. As a temporary workaround, limit the ability of remote authenticated users to make file-access attempts to minimize the risk of file enumeration.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3425

Affected Products

Cisco Webex