First published: Fri Mar 17 2017(Updated: )
An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting information on the Cisco WebEx Meetings Server. More Information: CSCvd50728. Known Affected Releases: 2.6 2.7 2.8 CWMS-2.5MR1 Orion1.1.2.patch T29_orion_merge.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Server | =2.5.1.5 | |
Cisco Webex Meetings Server | =2.5.1.29 | |
Cisco Webex Meetings Server | =2.5.99.2 | |
Cisco Webex Meetings Server | =2.5_base | |
Cisco Webex Meetings Server | =2.5_mr1 | |
Cisco Webex Meetings Server | =2.5_mr2 | |
Cisco Webex Meetings Server | =2.5_mr2-patch_1 | |
Cisco Webex Meetings Server | =2.5_mr3 | |
Cisco Webex Meetings Server | =2.5_mr4 | |
Cisco Webex Meetings Server | =2.5_mr5 | |
Cisco Webex Meetings Server | =2.5_mr5-patch_1 | |
Cisco Webex Meetings Server | =2.5_mr6 | |
Cisco Webex Meetings Server | =2.5_mr6-patch_1 | |
Cisco Webex Meetings Server | =2.5_mr6-patch_2 | |
Cisco Webex Meetings Server | =2.5_mr6-patch_3 | |
Cisco Webex Meetings Server | =2.5_mr6-patch_4 | |
Cisco Webex Meetings Server | =2.6.0 | |
Cisco Webex Meetings Server | =2.6.1.39 | |
Cisco Webex Meetings Server | =2.6_mr1 | |
Cisco Webex Meetings Server | =2.6_mr1-patch_1 | |
Cisco Webex Meetings Server | =2.6_mr2 | |
Cisco Webex Meetings Server | =2.6_mr2-patch_1 | |
Cisco Webex Meetings Server | =2.6_mr3 | |
Cisco Webex Meetings Server | =2.6_mr3-patch_1 | |
Cisco Webex Meetings Server | =2.6_mr3-patch_2 | |
Cisco Webex Meetings Server | =2.7.1 | |
Cisco Webex Meetings Server | =2.7_base | |
Cisco Webex Meetings Server | =2.7_mr1 | |
Cisco Webex Meetings Server | =2.7_mr1-patch_1 | |
Cisco Webex Meetings Server | =2.7_mr2 | |
Cisco Webex Meetings Server | =2.7_mr2-patch_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-3880 is rated as high due to its potential for authentication bypass.
To fix CVE-2017-3880, upgrade to affected versions of Cisco WebEx Meetings Server that have applied the necessary patches.
CVE-2017-3880 affects versions 2.5.x, 2.6.x, and 2.7.x of Cisco WebEx Meetings Server.
Yes, CVE-2017-3880 can potentially expose limited meeting information due to authentication bypass.
Any organization using the affected versions of Cisco WebEx Meetings Server could be impacted by CVE-2017-3880.