Cisco Webex Meetings Server vulnerabilities
106 known vulnerabilities affecting cisco/webex_meetings_server.
Total CVEs
106
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH59MEDIUM38LOW1
Vulnerabilities
Page 2 of 6
CVE-2020-3345MEDIUMCVSS 4.3≤ 4.0v4.02020-07-16
CVE-2020-3345 [MEDIUM] CWE-20 CVE-2020-3345: A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could a
A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser. The vulnerability is due to improper checks on parameter values within affected pages. An attacker could exploit this vulnerability by persuading a user to follow
nvd
CVE-2020-3361CRITICALCVSS 9.8fixed in 4.0v4.02020-06-18
CVE-2020-3361 [HIGH] CWE-287 CVE-2020-3361: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticat
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability by sending crafted requests to a vu
nvd
CVE-2020-3194HIGHCVSS 7.8fixed in 4.0v4.02020-04-15
CVE-2020-3194 [HIGH] CWE-119 CVE-2020-3194: A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player
A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (ARF) or the
nvd
CVE-2020-3126LOWCVSS 3.5vt39.32020-04-13
CVE-2020-3126 [LOW] CWE-284 CVE-2020-3126: vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authentica
vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes when a room host views shared multimedia files. An authenticated, remote attacker could exploit this vulnerability by using the host role
nvd
CVE-2020-3128HIGHCVSS 7.8fixed in 3.0v3.0+1 more2020-03-04
CVE-2020-3128 [HIGH] CWE-20 CVE-2020-3128: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored in either the Advanced Recording For
nvd
CVE-2020-3127HIGHCVSS 7.8fixed in 3.0v3.0+1 more2020-03-04
CVE-2020-3127 [HIGH] CWE-20 CVE-2020-3127: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored in either the Advanced Recording For
nvd
CVE-2019-15286HIGHCVSS 7.8v3.0mr2v4.0+1 more2019-11-26
CVE-2019-15286 [HIGH] CWE-119 CVE-2019-15286: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (
nvd
CVE-2019-15284HIGHCVSS 7.8v3.0mr2v4.0+1 more2019-11-26
CVE-2019-15284 [HIGH] CWE-119 CVE-2019-15284: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist due to insufficient validation of certain elements with a Webex recording stored in either the Advanced Recording Format (
nvd
CVE-2019-15987MEDIUMCVSS 5.3v4.02019-11-26
CVE-2019-15987 [MEDIUM] CWE-287 CVE-2019-15987: A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco
A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA protection in certain URLs. An attacker could exploit this vulnerability by se
nvd
CVE-2019-1954MEDIUMCVSS 6.1fixed in 4.0\(1\)2019-08-08
CVE-2019-1954 [MEDIUM] CWE-601 CVE-2019-1954: A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could
A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device. An attacker could exploit this vulne
nvd
CVE-2019-1924HIGHCVSS 7.8v2.8v3.0+2 more2019-08-07
CVE-2019-1924 [HIGH] CWE-119 CVE-2019-1924: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. A
nvd
CVE-2019-1925HIGHCVSS 7.8v2.8v3.0+2 more2019-08-07
CVE-2019-1925 [HIGH] CWE-119 CVE-2019-1925: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. A
nvd
CVE-2019-1929HIGHCVSS 7.8v2.8v3.0+2 more2019-08-07
CVE-2019-1929 [HIGH] CWE-119 CVE-2019-1929: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. A
nvd
CVE-2019-1927HIGHCVSS 7.8v2.8v3.0+2 more2019-08-07
CVE-2019-1927 [HIGH] CWE-119 CVE-2019-1927: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. A
nvd
CVE-2019-1926HIGHCVSS 7.8v2.8v3.0+2 more2019-08-07
CVE-2019-1926 [HIGH] CWE-119 CVE-2019-1926: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. A
nvd
CVE-2019-1928HIGHCVSS 7.8v2.8v3.0+2 more2019-08-07
CVE-2019-1928 [HIGH] CWE-119 CVE-2019-1928: Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Web
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. A
nvd
CVE-2019-1868HIGHCVSS 7.5v2.62019-06-05
CVE-2019-1868 [HIGH] CWE-16 CVE-2019-1868: A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an
A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to access sensitive system information. The vulnerability is due to improper access control to files within the web-based management interface. An attacker could exploit this vulnerability by sending a malicious request to a
nvd
CVE-2019-1771HIGHCVSS 7.8v2.8\(1\)v3.0\(1\)2019-05-15
CVE-2019-1771 [HIGH] CWE-119 CVE-2019-1771: A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webe
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An a
nvd
CVE-2019-1773HIGHCVSS 7.8fixed in 4.02019-05-15
CVE-2019-1773 [HIGH] CWE-119 CVE-2019-1773: A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webe
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An a
nvd
CVE-2019-1772HIGHCVSS 7.8v2.8\(1\)v3.0\(1\)2019-05-15
CVE-2019-1772 [HIGH] CWE-119 CVE-2019-1772: A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webe
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An a
nvd