Executive brief
A vulnerability in Cisco WebEx Meetings Server allows a logged-in user to change the passwords of other non-administrative users. This product is an on-premise conferencing solution for audio, video, and web meetings. If exploited, an attacker could gain unauthorized access to other employees' accounts, potentially leading to the exposure of sensitive meeting data or corporate communications.
Technical details
An improper authentication vulnerability (CWE-287/CWE-255) in Cisco WebEx Meetings Server is caused by insufficient parameter string security. An authenticated, remote attacker can exploit this by creating a password-protected meeting and manipulating system-provided parameters to trigger a password change for a targeted non-administrative user. Successful exploitation allows the attacker to reset the password of any non-admin account. The vulnerability is fixed in version 2.7.1.12.
Affected products
- Cisco WebEx Meetings Server 2.6
Timeline
- 2017-01-18: advisory: Initial Cisco advisory release
- 2017-01-26: disclosed: NVD publication date