PT-2020-2441 · Cisco · Cisco Webex Meetings Server

Published

2020-04-13

·

Updated

2020-04-14

·

CVE-2020-3126

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco Webex Meetings Server (affected versions not specified)
Description The issue is related to insufficient access control in the multimedia content viewing function of the software. This could allow a remote attacker to gain unauthorized access to protected information. The vulnerability is due to missing security warning dialog boxes when a room host views shared multimedia files. An authenticated, remote attacker could exploit this by sharing files within the Multimedia sharing feature and convincing a former room host to view the file, potentially leading to additional attacks by including malicious files within the targeted room host's browser window.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02450
CVE-2020-3126

Affected Products

Cisco Webex Meetings Server