PT-2020-3891 · Cisco · Cisco Meetings App

Published

2020-07-15

·

Updated

2020-07-22

·

CVE-2020-3197

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Meetings App (affected versions not specified)
Description: A vulnerability in the API subsystem could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials. The issue is due to insufficient protection mechanisms for these credentials. An attacker could exploit this by intercepting legitimate traffic, potentially obtaining the TURN server credentials to place audio/video calls and forward packets through the configured TURN server. However, the attacker would not be able to take control of the TURN server unless the same credentials were used in multiple systems.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04284
CVE-2020-3197

Affected Products

Cisco Meetings App