PT-2020-4221 · Cisco · Cisco Webex Meetings

Sai Kiran Battaluri

·

Published

2020-08-05

·

Updated

2021-08-06

·

CVE-2020-3472

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cisco Webex Meetings (affected versions not specified)
Description: A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The issue is due to improper access restrictions on users who are added within user contacts. An attacker could exploit this by sending specially crafted requests to the Webex Meetings site, potentially allowing them to view the details of users on another Webex site, including user names and email addresses.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04661
CVE-2020-3472

Affected Products

Cisco Webex Meetings