PT-2017-1535 · Cisco · Cisco Webex Meetings Server

Published

2017-03-17

·

Updated

2017-07-12

·

CVE-2017-3880

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco WebEx Meetings Server versions 2.5 through 2.8
Description The issue is related to insufficient authentication procedures in the software, potentially allowing a remote attacker to partially compromise the confidentiality and integrity of information. An unauthenticated, remote attacker could access limited meeting information on the Cisco WebEx Meetings Server.
Recommendations For versions 2.5 through 2.8, apply the necessary patches or updates to resolve the authentication bypass issue, specifically considering the patch T29 orion merge and the Orion1.1.2.patch update.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00680
CVE-2017-3880

Affected Products

Cisco Webex Meetings Server