First published: Wed Jul 31 2013(Updated: )
The Meeting Center component in Cisco WebEx 11 generates different error messages for invalid file-access attempts depending on whether a file exists, which allows remote authenticated users to enumerate files via a series of SPI calls, aka Bug ID CSCuc35965.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Platform | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3425 has been classified with a CVSS score indicating a medium severity level due to its potential impact on file enumeration.
To mitigate CVE-2013-3425, users should upgrade to a patched version of Cisco WebEx that addresses the file access enumeration issue.
CVE-2013-3425 affects users of Cisco WebEx version 11.0, specifically those accessing the Meeting Center component.
CVE-2013-3425 allows remote authenticated users to enumerate files, potentially leading to unauthorized access to sensitive information.
There are no documented workarounds for CVE-2013-3425; upgrading to a secure version is the recommended solution.