First published: Thu Oct 27 2016(Updated: )
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a Web Bridge user. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Meeting Server | =1.8.15 | |
Cisco Meeting Server | =1.8_base | |
Cisco Meeting Server | =1.9.0 | |
Cisco Meeting Server | =1.9.2 | |
Cisco Meeting Server | =2.0.0 | |
Cisco Meeting Server | =2.0.1 | |
Cisco Meeting Server | =2.0.3 | |
Cisco Meeting Server | =2.0.4 | |
Cisco Meeting Server | =2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6444 is classified as a medium severity vulnerability.
To fix CVE-2016-6444, upgrade the Cisco Meeting Server to a version that is not affected, such as 1.8.16 or later.
CVE-2016-6444 allows for cross-site request forgery (CSRF) attacks against Web Bridge users.
CVE-2016-6444 affects Cisco Meeting Server versions 1.8, 1.9, and 2.0.
No, CVE-2016-6444 can be exploited by an unauthenticated remote attacker.