CVE-2014-3305: CSRF
Published Jul 26, 2014
·Updated
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735.
Affected Software
3 affected components
Cisco Webex Meetings Server<=1.5\(.1.131\)
Cisco Webex Meetings Server=1.5
Cisco Webex Meetings Server=1.5\(.1.6\)
Event History
Jul 26, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3305?
CVE-2014-3305 is categorized as a high severity vulnerability due to its potential to allow remote attackers to hijack user authentication.
2
How do I fix CVE-2014-3305?
To mitigate the risk of CVE-2014-3305, it is recommended to upgrade to a version of Cisco WebEx Meetings Server later than 1.5(.1.131).
3
What does CVE-2014-3305 affect?
CVE-2014-3305 affects Cisco WebEx Meetings Server versions 1.5 and earlier.
4
What type of vulnerability is CVE-2014-3305?
CVE-2014-3305 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2014-3305 be exploited remotely?
Yes, CVE-2014-3305 can be exploited remotely by attackers to hijack victim authentication.