CVE-2020-3472: Cisco Webex Meetings User Email Address Information Disclosure Vulnerability
A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users who are added within user contacts. An attacker on one Webex Meetings site could exploit this vulnerability by sending specially crafted requests to the Webex Meetings site. A successful exploit could allow the attacker to view the details of users on another Webex site, including user names and email addresses.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3472?
CVE-2020-3472 is a vulnerability in the contacts feature of Cisco Webex Meetings that could allow an authenticated remote attacker to access sensitive information.
How does CVE-2020-3472 impact Cisco Webex Meetings?
CVE-2020-3472 allows an authenticated remote attacker with a legitimate user account to access sensitive information in Cisco Webex Meetings.
What is the severity of CVE-2020-3472?
CVE-2020-3472 has a severity rating of medium.
How do I fix CVE-2020-3472?
To fix CVE-2020-3472, users should update Cisco Webex Meetings to version 40.7.0 or later.
Are there any references for CVE-2020-3472?
Yes, you can find more information about CVE-2020-3472 at the following link: [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-mAkmV4qc).