CVE-2020-3441: Cisco Webex Meetings and Cisco Webex Meetings Server Information Disclosure Vulnerability
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information from the meeting room lobby. This vulnerability is due to insufficient protection of sensitive participant information. An attacker could exploit this vulnerability by browsing the Webex roster. A successful exploit could allow the attacker to gather information about other Webex participants, such as email address and IP address, while waiting in the lobby.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3441?
CVE-2020-3441 has a medium severity level due to its potential to expose sensitive participant information.
How do I fix CVE-2020-3441?
To fix CVE-2020-3441, update your affected Cisco Webex Meetings or Cisco Webex Meetings Server to the latest version provided by Cisco.
Which Cisco products are affected by CVE-2020-3441?
CVE-2020-3441 affects multiple versions of Cisco Webex Meetings and Cisco Webex Meetings Server, including versions up to 40.6.11 and 40.11.3.
Can CVE-2020-3441 be exploited remotely?
Yes, CVE-2020-3441 can be exploited by an unauthenticated remote attacker.
What kind of information can be accessed through CVE-2020-3441?
CVE-2020-3441 allows attackers to view sensitive participant information from the meeting room lobby.