Improper Control of Dynamically-Managed Code Resources in Cisco WebEx Meetings Server and Cisco Webex Meetings - CVE-2020-3419
Published: November 18, 2020 / Updated: November 19, 2020
Vulnerability details
The vulnerability allows a remote attacker to join a Webex session without appearing on the participant list.
The vulnerability exists due to improper handling of authentication tokens by a vulnerable Webex site. A remote attacker can send specially crafted requests and join meetings, without appearing in the participant list, while having full access to audio, video, chat, and screen sharing capabilities.
Affected software
Cisco Webex Meetings