CVE-2017-3811
published 2017-03-17CVE-2017-3811: An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the…
PriorityP337medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.43%
69.9th percentile
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.2054.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | — | — |
| cisco | webex_meetings_server_xml_external_entity | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-52pr-5rrw-jrw9: An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the i
ghsa_unreviewed·2022-05-17
CVE-2017-3811 [MEDIUM] CWE-611 GHSA-52pr-5rrw-jrw9: An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the i
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.2054.
Cisco
Cisco WebEx Meetings Server XML External Entity Vulnerability
vendor_cisco·2017-03-15·CVSS 6.5
CVE-2017-3811 [MEDIUM] CWE-20 Cisco WebEx Meetings Server XML External Entity Vulnerability
Cisco WebEx Meetings Server XML External Entity Vulnerability
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system.
The vulnerability is due to improper handling of an XML External Entity (XXE) when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted XML file to the affected system. A successful exploit could allow the attacker to have read access to part of the information stored in the affected system.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-wms
Cisco
Cisco WebEx Meetings Server XML External Entity Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3811 Cisco WebEx Meetings Server XML External Entity Vulnerability
CVE-2017-3811: Cisco WebEx Meetings Server XML External Entity Vulnerability
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. The vulnerability is due to improper handling of an XML External Entity (XXE) when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted XML file to the affected system. A successful exploit could allow the attacker to have read access to part of the information stored in the affected system. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvc39165
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96912http://www.securitytracker.com/id/1038042https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-wmshttp://www.securityfocus.com/bid/96912http://www.securitytracker.com/id/1038042https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-wms
2017-03-17
Published