Information disclosure in Cisco WebEx Meetings Server and Cisco Webex Meetings Desktop App - CVE-2021-1372

 

Information disclosure in Cisco WebEx Meetings Server and Cisco Webex Meetings Desktop App - CVE-2021-1372

Published: February 17, 2021


Vulnerability identifier: #VU50776
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1372
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to insecure usage of shared memory. A local user with permissions to view system memory can run a specially crafted program to read shared memory of the affected application and obtain sernames, meeting information, or authentication tokens.


Affected software

Cisco WebEx Meetings Server
Cisco Webex Meetings Desktop App

How to mitigate CVE-2021-1372

Install updates from vendor's website.

Cisco WebEx Meetings Server - update to 4.0MR3 Patch 4
Cisco Webex Meetings Desktop App - addressed in versions 40.6, 40.10

External References

Related Security Bulletins