Protection Mechanism Failure in Cisco WebEx Meetings Server and Cisco Webex Meetings - CVE-2021-1517

 

Protection Mechanism Failure in Cisco WebEx Meetings Server and Cisco Webex Meetings - CVE-2021-1517

Published: June 3, 2021


Vulnerability identifier: #VU53760
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1517
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to unsafe handling of shared content within the multimedia viewer feature. A remote authenticated attacker can bypass security protections and prevent warning dialogs from appearing before files are offered to other users.


Affected software

Cisco WebEx Meetings Server
Cisco Webex Meetings

How to mitigate CVE-2021-1517

Install updates from vendor's website.

Cisco WebEx Meetings Server - addressed in versions 3.0 MR4, 4.0 MR4
Cisco Webex Meetings - addressed in versions 3.0 MR4, 4.0 MR4

External References

Related Security Bulletins