imPC@ndo IT

Tracker / CVE-2020-3361

CVE-2020-3361

High 8.1

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Cisco Webex Meetings Server site. If successful, the attacker could gain the privileges of another user within the affected Webex site.

Affected products and versions

cisco webex_meetings
cisco webex_meetings · … → 39.5.25
cisco webex_meetings · 40.1.0 → 40.4.10
cisco webex_meetings_server
cisco webex_meetings_server · … → 4.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References