Improper Control of Dynamically-Managed Code Resources in Cisco WebEx Meetings Server and Cisco Webex Meetings - CVE-2020-3419

 

Improper Control of Dynamically-Managed Code Resources in Cisco WebEx Meetings Server and Cisco Webex Meetings - CVE-2020-3419

Published: November 18, 2020 / Updated: November 19, 2020


Vulnerability identifier: #VU48560
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-3419
CWE-ID: CWE-913
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to join a Webex session without appearing on the participant list.

The vulnerability exists due to improper handling of authentication tokens by a vulnerable Webex site. A remote attacker can send specially crafted requests and join meetings, without appearing in the participant list, while having full access to audio, video, chat, and screen sharing capabilities.


Affected software

Cisco WebEx Meetings Server
Cisco Webex Meetings

How to mitigate CVE-2020-3419

Install updates from vendor's website.

Cisco WebEx Meetings Server - addressed in versions 3.0MR3 Patch 5, 4.0MR3 Patch 4

External References

Related Security Bulletins