cbcvebase.
CVE-2020-3419
published 2020-11-18

CVE-2020-3419: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without…

PriorityP263critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.74%
75.2th percentile
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without appearing on the participant list. This vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Cisco Webex Meetings Server site. A successful exploit requires the attacker to have access to join a Webex meeting, including applicable meeting join links and passwords. The attacker could then exploit this vulnerability to join meetings, without appearing in the participant list, while having full access to audio, video, chat, and screen sharing capabilities.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_webex_meetings_server
ciscowebex_meetings_and_cisco_webex_meetings_server_ghost_join
ciscowebex_meetings_server< 3.03.0
ciscowebex_meetings_server
ciscowebex_meetings_server

Detection & IOCsextracted from sources · hover to see the quote

  • Detect crafted/anomalous authentication token requests to Webex Meetings sites — a participant who has joined but does not appear on the participant list may indicate exploitation of this ghost-join vulnerability.
  • Monitor for active audio/video/chat/screen-sharing sessions where the participant count or participant list does not match the number of active media streams, which may indicate a ghost participant.
  • Correlate Webex server-side authentication token handling logs for anomalous or malformed token submissions, referencing Cisco Bug IDs CSCvu42629 and CSCvu42755 for vendor patch/log guidance.
  • ·Exploitation requires the attacker to already possess a valid meeting join link and password — this is a prerequisite, not a bypass of meeting access controls entirely.
  • ·Both Cisco Webex Meetings (cloud) and Cisco Webex Meetings Server (on-premises) are affected; detection and patching scope must cover both deployment models.

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.