First published: Thu Oct 19 2017(Updated: )
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient limitations on the number of connections that can be made to the affected software. An attacker could exploit this vulnerability by opening multiple connections to the server and exhausting server resources. A successful exploit could cause the server to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf41006.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Server | =2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12293 is classified as a denial of service (DoS) vulnerability that allows attack disruption.
To mitigate CVE-2017-12293, it is recommended to update to a patched version of Cisco WebEx Meetings Server.
CVE-2017-12293 affects Cisco WebEx Meetings Server version 2.7 and potentially other versions if they are configured similarly.
CVE-2017-12293 can be exploited to execute a denial of service attack by overwhelming the server with connections.
No, CVE-2017-12293 can be exploited by unauthenticated remote attackers.