Information disclosure in Cisco WebEx Meetings Server and Cisco Webex Meetings - CVE-2020-3441

 

Information disclosure in Cisco WebEx Meetings Server and Cisco Webex Meetings - CVE-2020-3441

Published: November 18, 2020 / Updated: November 19, 2020


Vulnerability identifier: #VU48555
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3441
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to insufficient protection of sensitive participant information. A remote attacker can browse the Webex roster to gather information about other Webex participants, such as email address and IP address, while waiting in the lobby.


Affected software

Cisco WebEx Meetings Server
Cisco Webex Meetings

How to mitigate CVE-2020-3441

Install updates from vendor's website.

Cisco WebEx Meetings Server - addressed in versions 3.0MR3 Patch 5, 4.0MR3 Patch 4

External References

Related Security Bulletins