First published: Thu Nov 30 2017(Updated: )
A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information. The vulnerability is due to a design flaw in the product. An attacker could execute a query on an Event Center site to view scheduled meetings. A successful query would show both listed and unlisted meetings in the displayed information. An attacker could use this information to attend meetings that are not available for their attendance. Cisco Bug IDs: CSCvg33629.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco WebEx Meeting Center | =t32.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-12365.
The severity of CVE-2017-12365 is medium with a CVSS score of 4.3.
CVE-2017-12365 allows an authenticated remote attacker to view unlisted meeting information in Cisco WebEx Meeting Center.
Yes, Cisco has released a security advisory with fixes and mitigations for CVE-2017-12365.
You can find more information about CVE-2017-12365 in the following references: [link](http://www.securityfocus.com/bid/101999), [link](http://www.securitytracker.com/id/1039920), [link](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-webex4).