Cisco Webex Meetings vulnerabilities
51 known vulnerabilities affecting cisco/webex_meetings.
Total CVEs
51
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH14MEDIUM29
Vulnerabilities
Page 2 of 3
CVE-2020-3194P3HIGHCVSS 7.8≥ 39.5, < 39.5.182020-04-15
CVE-2020-3194 [HIGH] CWE-119 CVE-2020-3194: A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player
A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the
nvd
CVE-2020-3588P3HIGHCVSS 7.8fixed in 40.6.9≥ 40.8.0, < 40.8.92020-11-06
CVE-2020-3588 [HIGH] CWE-22 CVE-2020-3588: A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows
A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows could allow a local attacker to execute arbitrary code on a targeted system. This vulnerability occurs when this app is deployed in a virtual desktop environment and using virtual environment optimization. This vulnerability is due to improper validation of
nvd
CVE-2017-17428P3MEDIUMCVSS 5.9vt31vt322018-03-05
CVE-2017-17428 [MEDIUM] CWE-327 CVE-2017-17428: Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attacker
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
nvd
CVE-2020-3440P3MEDIUMCVSS 6.5fixed in 40.82020-08-26
CVE-2020-3440 [MEDIUM] CWE-22 CVE-2020-3440: A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an unauthenticated, remo
A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an unauthenticated, remote attacker to overwrite arbitrary files on an end-user system. The vulnerability is due to improper validation of URL parameters that are sent from a website to the affected application. An attacker could exploit this vulnerability by persuading a user
nvd
CVE-2019-1948P4MEDIUMCVSS 5.9≥ 11.3, ≤ 39.52019-08-21
CVE-2019-1948 [MEDIUM] CWE-295 CVE-2019-1948: A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker
A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by using an invalid Secure Sockets Layer (SSL) certificate. The vulnerability is due to insufficient SSL certificate validation by the affected software. An attacker could exploit this vulnerability by
nvd
CVE-2020-3441P4MEDIUMCVSS 5.3≤ 40.6.11≤ 40.11.32020-11-18
CVE-2020-3441 [MEDIUM] CWE-20 CVE-2020-3441: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticat
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information from the meeting room lobby. This vulnerability is due to insufficient protection of sensitive participant information. An attacker could exploit this vulnerability by browsing the Webex roster. A success
nvd
CVE-2019-15960P4MEDIUMCVSS 5.4fixed in 39.7.02019-11-26
CVE-2019-15960 [MEDIUM] CWE-264 CVE-2019-15960: A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an aut
A vulnerability in the Webex Network Recording Admin page of Cisco Webex Meetings could allow an authenticated, remote attacker to elevate privileges in the context of the affected page. To exploit this vulnerability, the attacker must be logged in as a low-level administrator. The vulnerability is due to insufficient access control validation. An a
nvd
CVE-2018-0357P4MEDIUMCVSS 6.1v1.3.52018-06-07
CVE-2018-0357 [MEDIUM] CWE-79 CVE-2018-0357: A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via the HTTP GET and HTTP
nvd
CVE-2018-0356P4MEDIUMCVSS 6.1vt322018-06-07
CVE-2018-0356 [MEDIUM] CWE-79 CVE-2018-0356: A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via the HTTP GET and HTTP
nvd
CVE-2022-20654P4MEDIUMCVSS 6.1v39.6v39.7+16 more2024-11-15
CVE-2022-20654 [MEDIUM] CWE-80 CVE-2022-20654: A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticat
A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based interface of Cisco Webex Meetings. An attacker could e
nvd
CVE-2021-1311P4MEDIUMCVSS 5.4fixed in 40.12.02021-01-13
CVE-2021-1311 [MEDIUM] CWE-307 CVE-2021-1311: A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Se
A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host key. An attacker could exploit this vulnerability by sending crafted requ
nvd
CVE-2026-20233P4MEDIUMCVSS 6.1v39.6.0v39.7.0+54 more2026-06-03
CVE-2026-20233 [MEDIUM] CWE-79 CVE-2026-20233: A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauth
A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed.
This vulnerability existed because of insufficient validation of user in
nvd
CVE-2018-0390P4MEDIUMCVSS 6.1v2.02018-07-18
CVE-2018-0390 [MEDIUM] CWE-79 CVE-2018-0390: A vulnerability in the web framework of Cisco Webex could allow an unauthenticated, remote attacker
A vulnerability in the web framework of Cisco Webex could allow an unauthenticated, remote attacker to conduct a Document Object Model-based (DOM-based) cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affe
nvd
CVE-2020-27126P4MEDIUMCVSS 6.1v40.10.22020-11-18
CVE-2020-27126 [MEDIUM] CWE-80 CVE-2020-27126: A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to
A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of user-supplied input to an application programmatic interface (API) within Cisco Webex Meetings. An attacker could exploit this vulnerability by convincing a targe
nvd
CVE-2021-1351P4MEDIUMCVSS 6.1v41.1.02021-02-17
CVE-2021-1351 [MEDIUM] CWE-80 CVE-2021-1351: A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, r
A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected service. The vulnerability is due to insufficient validation of user-supplied input by the web-based interface of the affected service
nvd
CVE-2023-20133P4MEDIUMCVSS 5.4v39.6v39.7+30 more2023-07-07
CVE-2023-20133 [MEDIUM] CWE-79 CVE-2023-20133: A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote at
A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.
This vulnerability exists because of insufficient validation of user-supplied input in Webex Events (classic) programs, email templates, and survey questions.
nvd
CVE-2021-1410P4MEDIUMCVSS 4.3v39.6v39.7+16 more2024-11-18
CVE-2021-1410 [MEDIUM] CWE-284 CVE-2021-1410: A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authent
A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization.
The vulnerability is due to insufficient authorization enforcement for requests to update distribution lists. An attacker could exploit this vulnerabili
nvd
CVE-2021-1372P4MEDIUMCVSS 5.5fixed in 40.6fixed in 40.102021-02-17
CVE-2021-1372 [MEDIUM] CWE-202 CVE-2021-1372: A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could a
A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. This vulnerability is due to the unsafe usage of shared memory by the affected software. An attacker with permissions to view system memory could exploi
nvd
CVE-2020-3347P4MEDIUMCVSS 5.5fixed in 40.4.12v40.6.02020-06-18
CVE-2020-3347 [MEDIUM] CWE-200 CVE-2020-3347: A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local
A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. The vulnerability is due to unsafe usage of shared memory that is used by the affected software. An attacker with permissions to view system memory could exploit this vulnerability b
nvd
CVE-2021-1544P4MEDIUMCVSS 5.5fixed in 41.4.02021-06-04
CVE-2021-1544 [MEDIUM] CWE-497 CVE-2021-1544: A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authent
A vulnerability in logging mechanisms of Cisco Webex Meetings client software could allow an authenticated, local attacker to gain access to sensitive information. This vulnerability is due to unsafe logging of application actions. An attacker could exploit this vulnerability by logging onto the local system and accessing files containing the logged d
nvd