First published: Thu Jan 15 2015(Updated: )
Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Server Software | =1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8034 has been classified as a medium severity vulnerability.
To mitigate CVE-2014-8034, consider implementing additional user verification methods or updating to a patched version of Cisco WebEx Meetings Server if available.
The risks include potential unauthorized access to accounts through brute-force attacks on the CAPTCHA.
CVE-2014-8034 remains relevant for systems running affected versions of Cisco WebEx Meetings Server.
CVE-2014-8034 specifically affects Cisco WebEx Meetings Server version 1.5.