PT-2020-3891 · Cisco · Cisco Meetings App
Published
2020-07-15
·
Updated
2020-07-22
·
CVE-2020-3197
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Cisco Meetings App (affected versions not specified)
Description:
A vulnerability in the API subsystem could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials. The issue is due to insufficient protection mechanisms for these credentials. An attacker could exploit this by intercepting legitimate traffic, potentially obtaining the TURN server credentials to place audio/video calls and forward packets through the configured TURN server. However, the attacker would not be able to take control of the TURN server unless the same credentials were used in multiple systems.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Meetings App