PT-2021-7445 · Cisco · Cisco Webex Meetings Server+1
Alexandros Zacharis
·
Published
2021-06-02
·
Updated
2021-06-15
·
CVE-2021-1517
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Webex Meetings Server (affected versions not specified)
Cisco Webex Meetings (affected versions not specified)
Description
The issue is related to the multimedia viewer feature of the software, where unsafe handling of shared content allows an attacker to bypass security protections. This could be exploited by sharing a file through the multimedia viewer feature, potentially preventing warning dialogs from appearing before files are offered to other users. The attacker must be authenticated and act remotely to exploit this issue.
Recommendations
For Cisco Webex Meetings Server, consider disabling the multimedia viewer feature until a patch is available.
For Cisco Webex Meetings, restrict access to the multimedia viewer feature to minimize the risk of exploitation.
As a temporary workaround, avoid sharing files through the multimedia viewer feature until the issue is resolved.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Webex Meetings
Cisco Webex Meetings Server