Junglewise Threat Intelligence

CVE-2016-9218: Cisco Hybrid Meeting Server CSRF in web interface

CVE-2016-9218 · Severity: high · CVSS 8.8 · Published 2017-01-26

Vendors: Cisco.

Executive brief

Cisco Hybrid Meeting Server, a platform used to integrate on-premises meeting equipment with cloud services, contains a security flaw in its web management interface. An attacker could trick an authorized user into clicking a malicious link, allowing the attacker to perform administrative actions or change settings without the user's knowledge. This could lead to unauthorized configuration changes or a complete takeover of the management interface.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web interface of Cisco Hybrid Meeting Server due to insufficient CSRF protections. The flaw allows a remote, unauthenticated attacker to execute arbitrary actions with the privileges of an authenticated user. To exploit this, an attacker must convince a targeted user to visit a malicious website or click a specially crafted link while they have an active session on the affected device's web interface. Successful exploitation enables the attacker to submit unauthorized requests to the device, potentially leading to configuration changes or account manipulation. While Cisco's advisory lists a lower CVSS score (5.4), the NVD assessment rates this as High (8.8) due to the potential for full impact on confidentiality, integrity, and availability.

Affected products

  • Cisco Hybrid Meeting Server 1.0

Timeline

  • 2017-01-18: advisory: Initial Cisco advisory release
  • 2017-01-26: disclosed: NVD publication date

References