PT-2019-3165 · Cisco · Cisco Webex Meetings Mobile

Published

2019-08-21

·

Updated

2019-10-09

·

CVE-2019-1948

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Webex Meetings Mobile (iOS) (affected versions not specified)
Description The issue is caused by insufficient Secure Sockets Layer (SSL) certificate validation, allowing an unauthenticated, remote attacker to gain unauthorized read access to sensitive data. An attacker could exploit this by supplying a crafted SSL certificate to an affected device, potentially conducting man-in-the-middle attacks to decrypt confidential information on user connections.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03154
CVE-2019-1948

Affected Products

Cisco Webex Meetings Mobile