Information disclosure in Cisco Meeting Server - CVE-2018-15446

 

Information disclosure in Cisco Meeting Server - CVE-2018-15446

Published: November 7, 2018 / Updated: November 8, 2018


Vulnerability identifier: #VU15767
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15446
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists due to improper protections on data that is returned from user meeting requests when the Guest access via ID and passcode option is set to Legacy mode. A remote attacker can send meeting requests, determine the values of meeting room unique identifiers and conduct further exploits.


Affected software

Cisco Meeting Server

How to mitigate CVE-2018-15446

Update to version 2.3.8.

Cisco Meeting Server - update to 2.3.8

External References

Related Security Bulletins