Cisco Webex Meetings vulnerabilities
51 known vulnerabilities affecting cisco/webex_meetings.
Total CVEs
51
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH14MEDIUM29
Vulnerabilities
Page 3 of 3
CVE-2021-1467P4MEDIUMCVSS 4.3fixed in 41.32021-04-08
CVE-2021-1467 [MEDIUM] CWE-284 CVE-2021-1467: A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings client of a targeted user of a meeting in which they ar
nvd
CVE-2021-1310P4MEDIUMCVSS 4.7fixed in 40.11.12021-01-13
CVE-2021-1310 [MEDIUM] CWE-601 CVE-2021-1310: A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthe
A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page, bypassing the warning mechanism that should prompt the user before the redirection. This vulnerability is due to improper input validation of the URL parameters in an HTTP request. A
nvd
CVE-2023-20180P4MEDIUMCVSS 4.3v39.6v39.7+30 more2023-07-07
CVE-2023-20180 [MEDIUM] CWE-352 CVE-2023-20180: A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote
A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
This vulnerability is due to insufficient CSRF protections for the web interface on an affected system. An attacker could exploit this vulnerability by persuading a u
nvd
CVE-2020-3345P4MEDIUMCVSS 4.3fixed in 40.6.02020-07-16
CVE-2020-3345 [MEDIUM] CWE-20 CVE-2020-3345: A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could a
A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser. The vulnerability is due to improper checks on parameter values within affected pages. An attacker could exploit this vulnerability by persuading a user to follow
nvd
CVE-2021-1221P4MEDIUMCVSS 4.1fixed in 41.1.02021-02-04
CVE-2021-1221 [MEDIUM] CWE-20 CVE-2021-1221: A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Softwa
A vulnerability in the user interface of Cisco Webex Meetings and Cisco Webex Meetings Server Software could allow an authenticated, remote attacker to inject a hyperlink into a meeting invitation email. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by entering a URL into a field in the user int
nvd
CVE-2015-6384P4MEDIUMCVSS 4.3v8.0_base2015-12-05
CVE-2015-6384 [MEDIUM] CWE-264 CVE-2015-6384: The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom applicat
The Cisco WebEx Meetings application before 8.5.1 for Android improperly initializes custom application permissions, which allows attackers to bypass intended access restrictions via a crafted application, aka Bug ID CSCuw86442.
nvd
CVE-2019-1677P4MEDIUMCVSS 4.6fixed in 11.7.0.2362019-02-07
CVE-2019-1677 [MEDIUM] CWE-79 CVE-2019-1677: A vulnerability in Cisco Webex Meetings for Android could allow an unauthenticated, local attacker t
A vulnerability in Cisco Webex Meetings for Android could allow an unauthenticated, local attacker to perform a cross-site scripting attack against the application. The vulnerability is due to insufficient validation of the application input parameters. An attacker could exploit this vulnerability by sending a malicious request to the Webex Meetings ap
nvd
CVE-2020-3182P4MEDIUMCVSS 4.3≤ 40.1.8.52020-03-04
CVE-2020-3182 [MEDIUM] CWE-200 CVE-2020-3182: A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client fo
A vulnerability in the multicast DNS (mDNS) protocol configuration of Cisco Webex Meetings Client for MacOS could allow an unauthenticated adjacent attacker to obtain sensitive information about the device on which the Webex client is running. The vulnerability exists because sensitive information is included in the mDNS reply. An attacker could explo
nvd
CVE-2020-3541P4MEDIUMCVSS 4.4fixed in 39.5.25≥ 40.6.0, < 40.6.62020-09-04
CVE-2020-3541 [MEDIUM] CWE-200 CVE-2020-3541: A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webe
A vulnerability in the media engine component of Cisco Webex Meetings Client for Windows, Cisco Webex Meetings Desktop App for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to gain access to sensitive information. The vulnerability is due to unsafe logging of authentication requests by the affected software. A
nvd
CVE-2020-3502P4MEDIUMCVSS 4.1fixed in 39.5.24≥ 40.4.0, < 40.4.6+2 more2020-08-17
CVE-2020-3502 [MEDIUM] CWE-20 CVE-2020-3502: Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an au
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker with a valid Webex account could explo
nvd
CVE-2020-3501P4MEDIUMCVSS 4.1fixed in 39.5.24≥ 40.4.0, < 40.4.6+2 more2020-08-17
CVE-2020-3501 [MEDIUM] CWE-20 CVE-2020-3501: Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an au
Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters returned to the application from a web site. An attacker with a valid Webex account could explo
nvd
← Previous3 / 3