Cisco Webex Meetings Server vulnerabilities
106 known vulnerabilities affecting cisco/webex_meetings_server.
Total CVEs
106
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH59MEDIUM38LOW1
Vulnerabilities
Page 1 of 6
CVE-2021-44228P1CRITICALCVSS 10.0KEVPoCRansomwarefixed in 3.0v3.0+1 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2017-3823P2HIGHCVSS 8.8PoCv2.0_basev2.0_mr2+21 more2017-02-01
CVE-2017-3823 [HIGH] CWE-119 CVE-2017-3823: An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on Internet Explorer. A vulnerability in th
nvd
CVE-2020-3419P2CRITICALCVSS 9.1fixed in 3.0v3.0+1 more2020-11-18
CVE-2020-3419 [CRITICAL] CWE-913 CVE-2020-3419: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticat
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to join a Webex session without appearing on the participant list. This vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability by sending crafted
nvd
CVE-2020-3361P2CRITICALCVSS 9.8fixed in 4.0v4.02020-06-18
CVE-2020-3361 [CRITICAL] CWE-287 CVE-2020-3361: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticat
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability by sending crafted requests to
nvd
CVE-2017-12368P3CRITICALCVSS 9.6v2.6v2.72017-11-30
CVE-2017-12368 [CRITICAL] CWE-119 CVE-2017-12368: A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx N
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file
nvd
CVE-2017-12372P3CRITICALCVSS 9.6v2.6v2.72017-11-30
CVE-2017-12372 [CRITICAL] CWE-119 CVE-2017-12372: A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx N
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file
nvd
CVE-2015-0589P3CRITICALCVSS 9.0v1.0v1.1+1 more2015-02-07
CVE-2015-0589 [CRITICAL] CWE-20 CVE-2015-0589: The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authen
The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands with root privileges via unspecified fields, aka Bug ID CSCuj40460.
nvd
CVE-2016-1482P3HIGHCVSS 8.1v2.6.02016-09-17
CVE-2016-1482 [HIGH] CWE-78 CVE-2016-1482: Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting t
Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug ID CSCuy83130.
nvd
CVE-2017-6753P3HIGHCVSS 8.8v1.1_basev1.5.1.6+13 more2017-07-25
CVE-2017-6753 [HIGH] CWE-119 CVE-2017-6753: A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow
A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event C
nvd
CVE-2016-1446P3HIGHCVSS 8.8v2.6.0v2.6.1.392016-07-15
CVE-2016-1446 [HIGH] CWE-89 CVE-2016-1446: SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to
SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.
nvd
CVE-2018-0112P3CRITICALCVSS 9.0v2.7v2.8+1 more2018-04-19
CVE-2018-0112 [CRITICAL] CWE-20 CVE-2018-0112: A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meeting
A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability is due to insufficient input validation by the Cisco WebEx clients. An attacker could exploit this vulnerability by providing meeti
nvd
CVE-2017-12367P3CRITICALCVSS 9.6vt29vt30+1 more2017-11-30
CVE-2017-12367 [CRITICAL] CWE-119 CVE-2017-12367: A "Cisco WebEx Network Recording Player Denial of Service Vulnerability" exists in Cisco WebEx Netwo
A "Cisco WebEx Network Recording Player Denial of Service Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a malicious ARF or WRF file via email or URL and convincing the user to launch the file. Ex
nvd
CVE-2017-12293P3HIGHCVSS 8.6v2.72017-10-19
CVE-2017-12293 [HIGH] CWE-119 CVE-2017-12293: A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to ca
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient limitations on the number of connections that can be made to the affected software. An attacker could exploit this vulnerability by opening multiple connections to the ser
nvd
CVE-2019-1868P3HIGHCVSS 7.5v2.62019-06-05
CVE-2019-1868 [HIGH] CWE-16 CVE-2019-1868: A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an
A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to access sensitive system information. The vulnerability is due to improper access control to files within the web-based management interface. An attacker could exploit this vulnerability by sending a malicious request to a
nvd
CVE-2017-6651P3HIGHCVSS 7.5v2.5.1.5v2.5.1.29+18 more2017-05-16
CVE-2017-6651 [HIGH] CWE-200 CVE-2017-6651: A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain
A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that could allow them to access scheduled customer meetings. The vulnerability is due to an incomplete configuration of the robots.txt file on customer-hosted WebEx solutions and occurs when the Short URL functionality is not activated. All r
nvd
CVE-2014-0691P3HIGHCVSS 7.3≤ 1.02017-10-24
CVE-2014-0691 [HIGH] CWE-331 CVE-2014-0691: Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it ea
Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643.
nvd
CVE-2020-3573P3HIGHCVSS 7.8v3.0v4.02020-11-06
CVE-2020-3573 [HIGH] CWE-119 CVE-2020-3573: Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Fo
nvd
CVE-2020-3603P3HIGHCVSS 7.8v3.0v4.02020-11-06
CVE-2020-3603 [HIGH] CWE-119 CVE-2020-3603: Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements of a Webex recording that is stored in the Advanced Recording Format (ARF) or Webex Recording Fo
nvd
CVE-2020-3127P3HIGHCVSS 7.8fixed in 3.0v3.0+1 more2020-03-04
CVE-2020-3127 [HIGH] CWE-20 CVE-2020-3127: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored in either the Advanced Recording For
nvd
CVE-2020-3128P3HIGHCVSS 7.8fixed in 3.0v3.0+1 more2020-03-04
CVE-2020-3128 [HIGH] CWE-20 CVE-2020-3128: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored in either the Advanced Recording For
nvd
1 / 6Next →