First published: Fri Jun 19 2015(Updated: )
The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether the username exists or corresponds to a privileged account, which allows remote attackers to enumerate account names and obtain sensitive information via a series of requests, aka Bug ID CSCuf28861.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebEx Meeting Center |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4194 is classified as having a medium severity level due to the potential for information disclosure.
To mitigate CVE-2015-4194, ensure that you are using the latest version of Cisco WebEx Meeting Center and implement proper access controls for account management.
CVE-2015-4194 can allow attackers to enumerate account names and potentially gain unauthorized access to sensitive information related to privileged accounts.
Users of Cisco WebEx Meeting Center who have not updated their software or secured their administrative interface are at risk from CVE-2015-4194.
A possible workaround for CVE-2015-4194 is to limit access to the web-based administrative interface to trusted IP addresses only.