PT-2017-1535 · Cisco · Cisco Webex Meetings Server
Published
2017-03-17
·
Updated
2017-07-12
·
CVE-2017-3880
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco WebEx Meetings Server versions 2.5 through 2.8
Description
The issue is related to insufficient authentication procedures in the software, potentially allowing a remote attacker to partially compromise the confidentiality and integrity of information. An unauthenticated, remote attacker could access limited meeting information on the Cisco WebEx Meetings Server.
Recommendations
For versions 2.5 through 2.8, apply the necessary patches or updates to resolve the authentication bypass issue, specifically considering the patch T29 orion merge and the Orion1.1.2.patch update.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Webex Meetings Server