First published: Wed Jun 02 2021(Updated: )
A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An attacker could exploit this vulnerability by logging onto the local system and accessing files containing the logged details. A successful exploit could allow the attacker to gain access to sensitive information, including meeting data and recorded meeting transcriptions. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-8fpBnKOz
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Webex Meetings Client |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-webex-8fpBnKOz is classified as high due to the potential for sensitive information leakage.
To fix cisco-sa-webex-8fpBnKOz, update the Cisco Webex Meetings client to the latest version provided by Cisco.
All authenticated users of the Cisco Webex Meetings client software are potentially affected by cisco-sa-webex-8fpBnKOz.
cisco-sa-webex-8fpBnKOz is caused by unsafe logging mechanisms in the Cisco Webex Meetings client.
cisco-sa-webex-8fpBnKOz could allow access to sensitive user information logged by the application.