Junglewise Threat Intelligence

CVE-2017-3794: Cisco WebEx Meetings Server CSRF in Administration pages

CVE-2017-3794 · Severity: high · CVSS 8.8 · Published 2017-01-26

Technologies: Cisco Webex Meetings Server. Vendors: Cisco.

Executive brief

Cisco WebEx Meetings Server is a private, virtualized conferencing solution for businesses. A security flaw in its administration interface could allow an attacker to trick a system administrator into performing unintended actions, such as changing settings or user permissions. This occurs if the administrator clicks a malicious link or visits a compromised website while logged into the WebEx management console.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Administration pages of Cisco WebEx Meetings Server due to insufficient CSRF protections. An unauthenticated, remote attacker can exploit this by inducing an authenticated administrative user to interact with a malicious link or website. If successful, the attacker can submit arbitrary requests to the affected device with the privileges of the targeted administrator. The vulnerability is tracked under Cisco Bug ID CSCuz03317 and is fixed in version 2.7.1.12.

Affected products

  • Cisco WebEx Meetings Server 2.6

Timeline

  • 2017-01-18: advisory: Initial Cisco advisory release
  • 2017-01-26: disclosed: NVD publication date

References

Related threats