First published: Thu Jul 10 2014(Updated: )
The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not verify that a requested file was an offered file, which allows remote attackers to read arbitrary files via a modified request, aka Bug IDs CSCup62442 and CSCup58463.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebEx Meeting Center | ||
Cisco Webex Meetings Server Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3310 is classified as a high severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2014-3310, update to the latest version of Cisco WebEx Meetings Client as provided in Cisco's security advisory.
Exploiting CVE-2014-3310 allows remote attackers to read arbitrary files on the affected systems.
CVE-2014-3310 affects Cisco WebEx Meetings Server and Cisco WebEx Meeting Center.
Yes, CVE-2014-3310 allows attackers to read files without proper verification of access permissions.