CVE-2018-0359
published 2018-06-21CVE-2018-0359: A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an…
PriorityP425medium5.5CVSS 3.0
AVLACLPRLUINSUCNIHAN
EPSS
0.38%
30.0th percentile
A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session identifier, aka Session Fixation. The vulnerability exists because the affected application does not assign a new session identifier to a user session when a user authenticates to the application. An attacker could exploit this vulnerability by using a hijacked session identifier to connect to the application through the web-based management interface. A successful exploit could allow the attacker to hijack an authenticated user's browser session. Cisco Bug IDs: CSCvi23787.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | meeting_server | — | — |
| cisco | meeting_server_session_fixation | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Meeting Server Session Fixation Vulnerability
vendor_cisco·2018-06-20·CVSS 4.0
CVE-2018-0359 [MEDIUM] CWE-384 Cisco Meeting Server Session Fixation Vulnerability
Cisco Meeting Server Session Fixation Vulnerability
A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session identifier.
The vulnerability exists because the affected application does not assign a new session identifier to a user session when a user authenticates to the application. An attacker could exploit this vulnerability by using a hijacked session identifier to connect to the application through the web-based management interface. A successful exploit could allow the attacker to hijack an authenticated user's browser session.
There are no workarounds that address this vulnerability.
This advisory is available at the following li
Cisco
Cisco Meeting Server Session Fixation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0359 Cisco Meeting Server Session Fixation Vulnerability
CVE-2018-0359: Cisco Meeting Server Session Fixation Vulnerability
A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session identifier. The vulnerability exists because the affected application does not assign a new session identifier to a user session when a user authenticates to the application. An attacker could exploit this vulnerability by using a hijacked session identifier to connect to the application through the web-based management interface. A successful exploit could allow the attacker to hijack an authenticated user's browser session. There are no
CVSS: 3.0
CWE: CWE-384, CWE-384
Bug IDs: CSCvi23787
GHSA
GHSA-469v-7rvc-6p7q: A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an u
ghsa_unreviewed·2022-05-13
CVE-2018-0359 [MEDIUM] CWE-384 GHSA-469v-7rvc-6p7q: A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an u
A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session identifier, aka Session Fixation. The vulnerability exists because the affected application does not assign a new session identifier to a user session when a user authenticates to the application. An attacker could exploit this vulnerability by using a hijacked session identifier to connect to the application through the web-based management interface. A successful exploit could allow the attacker to hijack an authenticated user's browser session. Cisco Bug IDs: CSCvi23787.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/104583http://www.securitytracker.com/id/1041174https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-cms-sfhttp://www.securityfocus.com/bid/104583http://www.securitytracker.com/id/1041174https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-cms-sf
2018-06-21
Published