CVE-2016-6444: CSRF
Published Oct 27, 2016
·Updated
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a Web Bridge user. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0.
Affected Software
9 affected components
Cisco Meeting Server=1.8.15
Cisco Meeting Server=1.8_base
Cisco Meeting Server=1.9.0
Cisco Meeting Server=1.9.2
Cisco Meeting Server=2.0.0
Cisco Meeting Server=2.0.1
Cisco Meeting Server=2.0.3
Cisco Meeting Server=2.0.4
Cisco Meeting Server=2.0.5
Event History
Oct 27, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-6444?
CVE-2016-6444 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-6444?
To fix CVE-2016-6444, upgrade the Cisco Meeting Server to a version that is not affected, such as 1.8.16 or later.
3
What kind of attack can be executed due to CVE-2016-6444?
CVE-2016-6444 allows for cross-site request forgery (CSRF) attacks against Web Bridge users.
4
Which Cisco Meeting Server versions are affected by CVE-2016-6444?
CVE-2016-6444 affects Cisco Meeting Server versions 1.8, 1.9, and 2.0.
5
Is authentication required to exploit CVE-2016-6444?
No, CVE-2016-6444 can be exploited by an unauthenticated remote attacker.