Cisco Webex Meetings vulnerabilities
50 known vulnerabilities affecting cisco/webex_meetings.
Total CVEs
50
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH14MEDIUM28
Vulnerabilities
Page 1 of 3
CVE-2021-1410MEDIUMCVSS 4.3v39.6v39.7+16 more2024-11-18
CVE-2021-1410 [MEDIUM] CWE-284 CVE-2021-1410: A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authent
A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization.
The vulnerability is due to insufficient authorization enforcement for requests to update distribution lists. An attacker could exploit this vulnerabili
nvd
CVE-2022-20654MEDIUMCVSS 6.1v39.6v39.7+16 more2024-11-15
CVE-2022-20654 [MEDIUM] CWE-80 CVE-2022-20654: A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticat
A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based interface of Cisco Webex Meetings. An attacker could e
nvd
CVE-2023-20133MEDIUMCVSS 5.4v39.6v39.7+30 more2023-07-07
CVE-2023-20133 [MEDIUM] CWE-79 CVE-2023-20133: A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote at
A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability exists because of insufficient validation of user-supplied input in Webex Events (classic) programs, email templates, and survey questions.
nvd
CVE-2023-20180MEDIUMCVSS 4.3v39.6v39.7+30 more2023-07-07
CVE-2023-20180 [MEDIUM] CWE-352 CVE-2023-20180: A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote
A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
This vulnerability is due to insufficient CSRF protections for the web interface on an affected system. An attacker could exploit this vulnerability by persuading a u
nvd
CVE-2021-1544MEDIUMCVSS 5.5fixed in 41.4.02021-06-04
CVE-2021-1544 [MEDIUM] CWE-497 CVE-2021-1544: A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authent
A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An attacker could exploit this vulnerability by logging onto the local system and accessing files containing the logged d
nvd
CVE-2021-1467MEDIUMCVSS 4.3fixed in 41.32021-04-08
CVE-2021-1467 [MEDIUM] CWE-284 CVE-2021-1467: A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they ar
nvd
CVE-2021-1372MEDIUMCVSS 5.5fixed in 40.6fixed in 40.102021-02-17
CVE-2021-1372 [MEDIUM] CWE-202 CVE-2021-1372: A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could a
A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. This vulnerability is due to the unsafe usage of shared memory by the affected software. An attacker with permissions to view system memory could exploi
nvd
CVE-2021-1351MEDIUMCVSS 6.1v41.1.02021-02-17
CVE-2021-1351 [MEDIUM] CWE-80 CVE-2021-1351: A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, r
A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected service
nvd
CVE-2021-1221MEDIUMCVSS 4.1fixed in 41.1.02021-02-04
CVE-2021-1221 [MEDIUM] CWE-20 CVE-2021-1221: A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Softwa
A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an authenticated, remote attacker to inject a hyperlink into a meeting invitation email. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by entering a URL into a field in the user int
nvd
CVE-2021-1311MEDIUMCVSS 5.4fixed in 40.12.02021-01-13
CVE-2021-1311 [MEDIUM] CWE-307 CVE-2021-1311: A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Se
A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host key. An attacker could exploit this vulnerability by sending crafted requ
nvd
CVE-2021-1310MEDIUMCVSS 4.7fixed in 40.11.12021-01-13
CVE-2021-1310 [MEDIUM] CWE-601 CVE-2021-1310: A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthe
A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page, bypassing the warning mechanism that should prompt the user before the redirection. This vulnerability is due to improper input validation of the URL parameters in an HTTP request. A
nvd
CVE-2020-27126MEDIUMCVSS 6.1v40.10.22020-11-18
CVE-2020-27126 [MEDIUM] CWE-80 CVE-2020-27126: A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to
A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of user-supplied input to an application programmatic interface (API) within Cisco Webex Meetings. An attacker could exploit this vulnerability by convincing a targe
nvd
CVE-2020-3441MEDIUMCVSS 5.3≤ 40.6.11≤ 40.11.32020-11-18
CVE-2020-3441 [MEDIUM] CWE-20 CVE-2020-3441: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticat
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information from the meeting room lobby. This vulnerability is due to insufficient protection of sensitive participant information. An attacker could exploit this vulnerability by browsing the Webex roster. A success
nvd
CVE-2020-3604HIGHCVSS 7.8fixed in 40.6.11≥ 40.7.0, < 40.8.02020-11-06
CVE-2020-3604 [HIGH] CWE-119 CVE-2020-3604: Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Fo
nvd
CVE-2020-3603HIGHCVSS 7.8fixed in 40.6.11≥ 40.7.0, < 40.8.02020-11-06
CVE-2020-3603 [HIGH] CWE-119 CVE-2020-3603: Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Fo
nvd
CVE-2020-3573HIGHCVSS 7.8≥ 40.6.0, < 40.6.11≥ 40.7.0, < 40.8.02020-11-06
CVE-2020-3573 [HIGH] CWE-119 CVE-2020-3573: Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Fo
nvd
CVE-2020-3588HIGHCVSS 7.8fixed in 40.6.9≥ 40.8.0, < 40.8.92020-11-06
CVE-2020-3588 [HIGH] CWE-22 CVE-2020-3588: A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows
A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows could allow a local attacker to execute arbitrary code on a targeted system. This vulnerability occurs when this app is deployed in a virtual desktop environment and using virtual environment optimization. This vulnerability is due to improper validation of
nvd
CVE-2019-15287HIGHCVSS 7.8≥ 39.5.0, < 39.5.122020-09-23
CVE-2019-15287 [HIGH] CWE-119 CVE-2019-15287: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (
nvd
CVE-2019-15283HIGHCVSS 7.8≥ 39.5.0, < 39.5.122020-09-23
CVE-2019-15283 [HIGH] CWE-119 CVE-2019-15283: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (
nvd
CVE-2019-15285HIGHCVSS 7.8≥ 39.5.0, < 39.5.122020-09-23
CVE-2019-15285 [HIGH] CWE-119 CVE-2019-15285: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (
nvd
1 / 3Next →