← Back

CVE-2020-3361

nvd nist
Published: Jun 18, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Cisco Webex Meetings Server site. If successful, the attacker could gain the privileges of another user within the affected Webex site.

Affected (8)

2 products
Webex Meetings
Webex Meetings Server
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Up to 39.5.25
From 40.1.0 to 40.4.10
Version 40.6.0
Cisco
Before 4.0
Version 4.0
Version 4.0 maintenance_release1
Version 4.0 maintenance_release2
Version 4.0 maintenance_release3

Timeline

No history available yet.