CVE-2017-12297

Severity
5.0MEDIUM
EPSS
0.2%
top 53.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 30
Latest updateMay 13

Description

A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to arbitrary hosts, aka a "URL Redirection Vulnerability." The vulnerability is due to insufficient access control for HTTP traffic directed to the Cisco WebEx Meeting Center. An attacker could exploit this vulnerability by sending a malicious URL to the Cisco WebEx Meeting Center. An exploit could allow the attacker to connect to arbitrary hosts. Cisco Bug IDs: CSCvf63843.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:NExploitability: 3.1 | Impact: 1.4

Affected Packages2 packages

CVEListV5cisco_webex_meeting_centerCisco WebEx Meeting Center
NVDcisco/webex_meeting_center8 versions+7

🔴Vulnerability Details

2
GHSA
GHSA-8cqv-cr49-hx39: A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to arbitrary hosts, aka a "URL Red2022-05-13
CVEList
CVE-2017-12297: A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to arbitrary hosts, aka a "URL Red2017-11-30

📋Vendor Advisories

1
Cisco
Cisco WebEx Meeting Center URL Redirection Vulnerability2017-11-29
CVE-2017-12297 (MEDIUM CVSS 5) | A vulnerability in Cisco WebEx Meet | cvebase.io