cbcvebase.

Cisco Webex Meetings Server vulnerabilities

106 known vulnerabilities affecting cisco/webex_meetings_server.

Total CVEs
106
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH59MEDIUM38LOW1

Vulnerabilities

Page 4 of 6
CVE-2021-1536P3HIGHCVSS 7.8v4.02021-06-04
CVE-2021-1536 [HIGH] CWE-427 CVE-2021-1536: A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on t
nvd
CVE-2015-4276P3MEDIUMCVSS 6.5v2.5\(1\)2015-07-16
CVE-2015-4276 [MEDIUM] CWE-20 CVE-2015-4276: Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a crafted command parameter, aka Bug ID CSCus56138.
nvd
CVE-2017-3880P3MEDIUMCVSS 6.5v2.5.1.5v2.5.1.29+17 more2017-03-17
CVE-2017-3880 [MEDIUM] CWE-287 CVE-2017-3880: An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting information on the Cisco WebEx Meetings Server. More Information: CSCvd50728. Known Affected Releases: 2.6 2.7 2.8 CWMS-2.5MR1 Orion1.1.2.patch T29_orion_merge.
nvd
CVE-2019-1771P3HIGHCVSS 7.8v2.8\(1\)v3.0\(1\)2019-05-15
CVE-2019-1771 [HIGH] CWE-119 CVE-2019-1771: A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webe A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An a
nvd
CVE-2016-1448P3HIGHCVSS 8.8v2.7.1v2.7_base2016-07-17
CVE-2016-1448 [HIGH] CWE-352 CVE-2016-1448: Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote att Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuy92706.
nvd
CVE-2018-15431P3HIGHCVSS 7.3v3.02018-10-05
CVE-2018-15431 [HIGH] CWE-20 CVE-2018-15431: A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webe A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An
nvd
CVE-2020-3471P3MEDIUMCVSS 6.5fixed in 3.0v3.0+1 more2020-11-18
CVE-2020-3471 [MEDIUM] CWE-20 CVE-2020-3471: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticat A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to maintain bidirectional audio despite being expelled from an active Webex session. The vulnerability is due to a synchronization issue between meeting and media services on a vulnerable Webex site. An attacker could exploit this vul
nvd
CVE-2017-3811P3MEDIUMCVSS 6.5v2.62017-03-17
CVE-2017-3811 [MEDIUM] CWE-611 CVE-2017-3811: An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, re An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.2054.
nvd
CVE-2016-1483P3HIGHCVSS 7.5v2.6.02016-09-19
CVE-2016-1483 [HIGH] CWE-20 CVE-2016-1483: Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumptio Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation component of an unspecified service, aka Bug ID CSCuy92704.
nvd
CVE-2018-0422P3HIGHCVSS 7.3≤ 3.0v3.02018-10-05
CVE-2018-0422 [HIGH] CWE-732 CVE-2018-0422: A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. The vulnerability is due to folder permissions that grant a user the permission to read, write, and execute files in th
nvd
CVE-2017-12359P3MEDIUMCVSS 6.5v2.6.0v2.7.02017-11-30
CVE-2017-12359 [MEDIUM] CWE-119 CVE-2017-12359: A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Forma A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (.arf) files could allow an attacker to execute arbitrary code on a system. An attacker could exploit this vulnerability by providing a user with a malicious .arf file via email or URL and convincing the user to launch the file. Exploitation of this
nvd
CVE-2015-0597P4MEDIUMCVSS 5.0≤ 1.5\(.1.131\)2015-02-02
CVE-2015-0597 [MEDIUM] CWE-20 CVE-2015-0597: The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote att The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159.
nvd
CVE-2017-12363P4MEDIUMCVSS 5.3v2.6.0.8v2.72017-11-30
CVE-2017-12363 [MEDIUM] CWE-264 CVE-2017-12363: A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to mod A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affected system. The vulnerability is due to insufficient security settings on meetings. An attacker could exploit this vulnerability by modifying the welcome message to a meeting. A successful exploit could
nvd
CVE-2017-3797P4MEDIUMCVSS 5.3v2.7.1v2.7_base2017-01-26
CVE-2017-3797 [MEDIUM] CWE-200 CVE-2017-3797: A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to vi A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view the fully qualified domain name of the Cisco WebEx administration server. More Information: CSCvb60655. Known Affected Releases: 2.7.
nvd
CVE-2019-15987P4MEDIUMCVSS 5.3v4.02019-11-26
CVE-2019-15987 [MEDIUM] CWE-287 CVE-2019-15987: A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account usernames. The vulnerability is due to missing CAPTCHA protection in certain URLs. An attacker could exploit this vulnerability by se
nvd
CVE-2017-3795P4MEDIUMCVSS 5.4v2.6.02017-01-26
CVE-2017-3795 [MEDIUM] CWE-287 CVE-2017-3795: A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to cond A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct arbitrary password changes against any non-administrative user. More Information: CSCuz03345. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.12.
nvd
CVE-2014-3395P4MEDIUMCVSS 5.0v2.52014-09-30
CVE-2014-3395 [MEDIUM] CWE-20 CVE-2014-3395: Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary f Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary files via a crafted URL, aka Bug ID CSCup10343.
nvd
CVE-2020-3441P4MEDIUMCVSS 5.3fixed in 3.0v3.0+1 more2020-11-18
CVE-2020-3441 [MEDIUM] CWE-20 CVE-2020-3441: A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticat A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information from the meeting room lobby. This vulnerability is due to insufficient protection of sensitive participant information. An attacker could exploit this vulnerability by browsing the Webex roster. A success
nvd
CVE-2021-1311P4MEDIUMCVSS 5.4fixed in 3.0v3.0+1 more2021-01-13
CVE-2021-1311 [MEDIUM] CWE-307 CVE-2021-1311: A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Se A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host key. An attacker could exploit this vulnerability by sending crafted requ
nvd
CVE-2016-1389P4HIGHCVSS 7.4v2.6.02016-04-28
CVE-2016-1389 [HIGH] CVE-2016-1389: Open redirect vulnerability in Cisco WebEx Meetings Server (CWMS) 2.6 allows remote attackers to red Open redirect vulnerability in Cisco WebEx Meetings Server (CWMS) 2.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuy44695.
nvd
Cisco Webex Meetings Server vulnerabilities | cvebase