CVE-2017-3880: Medium severity Cisco Webex Meetings Server vulnerability
An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting information on the Cisco WebEx Meetings Server. More Information: CSCvd50728. Known Affected Releases: 2.6 2.7 2.8 CWMS-2.5MR1 Orion1.1.2.patch T29orionmerge.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco WebEx Meetings Serverto a version that resolves this vulnerability.Fixed in 2.6 - Upgrade
Upgrade
Cisco WebEx Meetings Serverto a version that resolves this vulnerability.Fixed in 2.7 - Upgrade
Upgrade
Cisco WebEx Meetings Serverto a version that resolves this vulnerability.Fixed in 2.8 - Upgrade
Upgrade
Cisco WebEx Meetings Serverto a version that resolves this vulnerability.Fixed in CWMS-2.5MR1 Orion1.1.2.patch T29_orion_merge - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CSCvd50728
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3880?
The severity of CVE-2017-3880 is rated as high due to its potential for authentication bypass.
How do I fix CVE-2017-3880?
To fix CVE-2017-3880, upgrade to affected versions of Cisco WebEx Meetings Server that have applied the necessary patches.
Which versions of Cisco WebEx Meetings Server are affected by CVE-2017-3880?
CVE-2017-3880 affects versions 2.5.x, 2.6.x, and 2.7.x of Cisco WebEx Meetings Server.
Can CVE-2017-3880 lead to data exposure?
Yes, CVE-2017-3880 can potentially expose limited meeting information due to authentication bypass.
Who is impacted by CVE-2017-3880?
Any organization using the affected versions of Cisco WebEx Meetings Server could be impacted by CVE-2017-3880.