CVE-2014-3301
published 2014-07-26CVE-2014-3301: The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading…
PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.85%
76.6th percentile
The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | <= 1.5\(.1.131\) | — |
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wr8c-v7j8-rh39: The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1
ghsa_unreviewed·2022-05-17
CVE-2014-3301 [MEDIUM] CWE-200 GHSA-wr8c-v7j8-rh39: The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1
The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned messages, aka Bug ID CSCuj81700.
Cisco
Cisco WebEx Meetings Server Stack Trace Vulnerability
vendor_cisco·2014-07-25·CVSS 5.0
CVE-2014-3301 [MEDIUM] CWE-200 Cisco WebEx Meetings Server Stack Trace Vulnerability
Cisco WebEx Meetings Server Stack Trace Vulnerability
A vulnerability in the ProfileAction controller of Cisco WebEx Meetings Server (CWMS) could allow an unauthenticated, remote attacker to view sensitive information.
The vulnerability is due to improper sanitization of returned messages. An attacker could exploit this vulnerability by submitting crafted URL requests to a vulnerable device.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/60573http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3301http://tools.cisco.com/security/center/viewAlert.x?alertId=35040http://www.securityfocus.com/bid/68894http://www.securitytracker.com/id/1030642https://exchange.xforce.ibmcloud.com/vulnerabilities/94895http://secunia.com/advisories/60573http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3301http://tools.cisco.com/security/center/viewAlert.x?alertId=35040http://www.securityfocus.com/bid/68894http://www.securitytracker.com/id/1030642https://exchange.xforce.ibmcloud.com/vulnerabilities/94895
2014-07-26
Published