CVE-2015-0597
published 2015-02-02CVE-2015-0597: The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted…
PriorityP432medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.55%
83.2th percentile
The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | <= 1.5\(.1.131\) | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco WebEx Meetings Server User Enumeration Vulnerability
vendor_cisco·2015-01-30·CVSS 5.0
CVE-2015-0597 [MEDIUM] CWE-20 Cisco WebEx Meetings Server User Enumeration Vulnerability
Cisco WebEx Meetings Server User Enumeration Vulnerability
A vulnerability in the Forgot Password process of the Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to enumerate a valid administrator account.
The vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by submitting crafted packets to a vulnerable device.
Cisco has confirmed the vulnerability in a security notice and released updated software.
To exploit the vulnerability, the attacker may need access to trusted or internal networks to transmit crafted packets to the targeted system. This access requirement could limit the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exists; however, the
GHSA
GHSA-83c5-28q2-824v: The Forgot Password feature in Cisco WebEx Meetings Server 1
ghsa_unreviewed·2022-05-17
CVE-2015-0597 [MEDIUM] CWE-20 GHSA-83c5-28q2-824v: The Forgot Password feature in Cisco WebEx Meetings Server 1
The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0597http://tools.cisco.com/security/center/viewAlert.x?alertId=37240http://www.securityfocus.com/bid/72373http://www.securitytracker.com/id/1031678https://exchange.xforce.ibmcloud.com/vulnerabilities/100658http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0597http://tools.cisco.com/security/center/viewAlert.x?alertId=37240http://www.securityfocus.com/bid/72373http://www.securitytracker.com/id/1031678https://exchange.xforce.ibmcloud.com/vulnerabilities/100658
2015-02-02
Published