CVE-2014-8034
published 2015-01-15CVE-2014-8034: Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.37%
68.7th percentile
Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.8HIGH
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco WebEx Meetings Server User Enumeration Vulnerability
vendor_cisco·2015-01-14·CVSS 5.0
CVE-2014-8034 [MEDIUM] CWE-200 Cisco WebEx Meetings Server User Enumeration Vulnerability
Cisco WebEx Meetings Server User Enumeration Vulnerability
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to guess valid user accounts on the targeted system.
The vulnerability exists because the affected software fails to refresh the CAPTCHA on the login page. An attacker could exploit this vulnerability by conducting unlimited user account guessing attempts against an affected server. A successful exploit may allow an attacker to discover valid user accounts on the server.
Cisco has confirmed the vulnerability and released updated software.
To exploit the vulnerability, the attacker may need to have access to trusted or internal networks to conduct brute-force attacks against the targeted system. This access requirement could limit the
GHSA
GHSA-27fc-vfp8-wfj8: Cisco WebEx Meetings Server 1
ghsa_unreviewed·2022-05-17
CVE-2014-8034 [MEDIUM] GHSA-27fc-vfp8-wfj8: Cisco WebEx Meetings Server 1
Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8034http://tools.cisco.com/security/center/viewAlert.x?alertId=36990http://www.securityfocus.com/bid/71978http://www.securitytracker.com/id/1031543https://exchange.xforce.ibmcloud.com/vulnerabilities/100552http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8034http://tools.cisco.com/security/center/viewAlert.x?alertId=36990http://www.securityfocus.com/bid/71978http://www.securitytracker.com/id/1031543https://exchange.xforce.ibmcloud.com/vulnerabilities/100552
2015-01-15
Published