CVE-2017-3880Improper Authentication in Cisco Webex Meetings Server

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 40.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 17
Latest updateMay 17

Description

An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting information on the Cisco WebEx Meetings Server. More Information: CSCvd50728. Known Affected Releases: 2.6 2.7 2.8 CWMS-2.5MR1 Orion1.1.2.patch T29_orion_merge.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages2 packages

NVDcisco/webex_meetings_server19 versions+18
CVEListV5cisco/cisco_webex_meetings_serverCisco WebEx Meetings Server

🔴Vulnerability Details

2
GHSA
GHSA-h6ph-8m27-fx8c: An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting inform2022-05-17
CVEList
CVE-2017-3880: An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting inform2017-03-17

📋Vendor Advisories

1
Cisco
Cisco WebEx Meetings Server Authentication Bypass Vulnerability2017-03-15
CVE-2017-3880 — Improper Authentication in Cisco | cvebase