CVE-2017-3795: Medium severity Cisco Webex Meetings Server vulnerability
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct arbitrary password changes against any non-administrative user. More Information: CSCuz03345. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco WebEx Meetings Serverto a version that resolves this vulnerability.Fixed in 2.7.1.12Patch CSCuz03345
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3795?
CVE-2017-3795 has a high severity due to the potential for authenticated remote attackers to change passwords for non-administrative users.
How do I fix CVE-2017-3795?
To fix CVE-2017-3795, upgrade to the fixed release version 2.7.1.12 or later of Cisco WebEx Meetings Server.
What impact does CVE-2017-3795 have on users?
CVE-2017-3795 allows attackers to conduct arbitrary password changes, compromising user accounts.
Is there a workaround for CVE-2017-3795?
There is no known workaround for CVE-2017-3795; upgrading to a fixed release is necessary.
Which versions of Cisco WebEx Meetings Server are affected by CVE-2017-3795?
CVE-2017-3795 affects Cisco WebEx Meetings Server version 2.6.0.