CVE-2017-12365Sensitive Information Exposure in Cisco Webex Event Center

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 51.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateMay 13

Description

A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information. The vulnerability is due to a design flaw in the product. An attacker could execute a query on an Event Center site to view scheduled meetings. A successful query would show both listed and unlisted meetings in the displayed information. An attacker could use this information to attend meetings that are not available for their attendance. Cisco Bug IDs: CSCvg33629.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5cisco/cisco_webex_event_centerCisco WebEx Event Center

🔴Vulnerability Details

2
GHSA
GHSA-r2vf-x75v-28pc: A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information2022-05-13
CVEList
CVE-2017-12365: A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information2017-11-30

📋Vendor Advisories

1
Cisco
Cisco WebEx Event Center Information Disclosure Vulnerability2017-11-29
CVE-2017-12365 — Sensitive Information Exposure | cvebase