CVE-2014-0682: Medium severity Cisco Webex Meetings Server vulnerability
Published Jan 29, 2014
·Updated
Cisco WebEx Meetings Server allows remote authenticated users to bypass authorization checks and (1) join arbitrary meetings, or (2) terminate a meeting without having a host role, via a crafted URL, aka Bug ID CSCuj42346.
Affected Software
1 affected component
Cisco Webex Meetings Server
Event History
Jan 29, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·06:34 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who is exposed to this issue?
Cisco WebEx Meetings Server deployments are exposed if an attacker has valid authentication to the server. The issue is remotely exploitable and does not require the attacker to hold a meeting host role.
2
What can an authenticated attacker do?
An authenticated attacker can use a crafted URL to bypass authorization checks and join arbitrary meetings. They can also terminate a meeting despite not having the host role.
3
Does exploitation require credentials?
Yes. The reported attack vector requires authentication, so unauthenticated remote users are not described as able to exploit this issue.