Protection Mechanism Failure in Cisco WebEx Meetings Server and Cisco Webex Meetings - CVE-2021-1517
Published: June 3, 2021
Vulnerability identifier: #VU53760
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1517
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to unsafe handling of shared content within the multimedia viewer feature. A remote authenticated attacker can bypass security protections and prevent warning dialogs from appearing before files are offered to other users.
Affected software
Cisco WebEx Meetings Server
Cisco Webex Meetings
Cisco Webex Meetings
How to mitigate CVE-2021-1517
Install updates from vendor's website.
Cisco WebEx Meetings Server - addressed in versions 3.0 MR4, 4.0 MR4
Cisco Webex Meetings - addressed in versions 3.0 MR4, 4.0 MR4
Cisco Webex Meetings - addressed in versions 3.0 MR4, 4.0 MR4