SB2020072115 - Improper Authentication in Cisco Meetings App



SB2020072115 - Improper Authentication in Cisco Meetings App

Published: July 21, 2020

Security Bulletin ID SB2020072115
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2020-3197)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to insufficient protection mechanisms for the TURN server credentials. A remote attacker can intercept the legitimate traffic that is generated by an affected system, bypass authentication process and obtain the TURN server credentials.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.