Junglewise Threat Intelligence

CVE-2017-3796: Cisco WebEx Meetings Server command injection in interactive bash

CVE-2017-3796 · Severity: high · CVSS 7.2 · Published 2017-01-26

Technologies: Cisco Webex Meetings Server. Vendors: Cisco.

Executive brief

Cisco WebEx Meetings Server is a private conferencing platform for audio, video, and web meetings. A vulnerability in this system could allow a user who already has administrative access to one part of the system to run unauthorized commands on other connected servers. This could lead to a complete takeover of the entire conferencing infrastructure and potential access to sensitive meeting data.

Technical details

An OS command injection vulnerability (CWE-78) exists in Cisco WebEx Meetings Server due to insufficient security configurations of bash in interactive mode. An authenticated, remote attacker with high privileges can exploit this by connecting to a host as root and then initiating an SSH connection to another host within the cluster. By issuing specific predetermined shell commands, the attacker can execute arbitrary commands with root privileges on any other host in the WebEx Meeting Server environment. At the time of advisory publication, no software updates or workarounds were available.

Affected products

  • Cisco WebEx Meetings Server 2.6

Timeline

  • 2017-01-18: advisory: Initial Cisco advisory release
  • 2017-01-26: disclosed: NVD publication date

References

Related threats