First published: Thu Jan 18 2018(Updated: )
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vulnerability is due to a design flaw in Cisco WebEx Meetings Server, which could include internal network information that should be restricted. An attacker could exploit the vulnerability by utilizing available resources to study the customer network. An exploit could allow the attacker to discover sensitive data about the application. Cisco Bug IDs: CSCvg46806.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Server Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2018-0111 vulnerability is rated as high severity due to its potential for information disclosure.
To remediate CVE-2018-0111, users should apply the latest patches released by Cisco for WebEx Meetings Server.
CVE-2018-0111 can facilitate reconnaissance attacks by allowing unauthorized access to sensitive application data.
CVE-2018-0111 affects all versions of Cisco WebEx Meetings Server prior to the security updates.
CVE-2018-0111 is an unauthenticated vulnerability, allowing attackers to exploit it without needing valid credentials.