First published: Thu Oct 27 2016(Updated: )
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated, remote attacker to masquerade as a legitimate user. This vulnerability is due to the XMPP service incorrectly processing a deprecated authentication scheme. A successful exploit could allow an attacker to access the system as another user.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Meeting Server | =1.8.15 | |
Cisco Meeting Server | =1.8_base | |
Cisco Meeting Server | =1.9.0 | |
Cisco Meeting Server | =1.9.2 | |
Cisco Meeting Server | =2.0.0 | |
Cisco Meeting Server | =2.0.1 | |
Cisco Meeting Server | =2.0.3 | |
Cisco Meeting Server | =2.0.4 | |
Cisco Meeting Server | =2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6445 has a high severity rating due to its potential for unauthorized access to user accounts.
To mitigate CVE-2016-6445, upgrade to Cisco Meeting Server version 2.0.6 or later, or Acano Server version 1.8.18 or 1.9.6 or later.
CVE-2016-6445 affects Cisco Meeting Server versions 1.8.15, 1.9.0, 1.9.2, and all 2.0.x versions prior to 2.0.6.
An attacker exploiting CVE-2016-6445 could masquerade as a legitimate user, potentially gaining unauthorized access to the system.
CVE-2016-6445 was disclosed on October 12, 2016.