Junglewise Threat Intelligence

CVE-2017-3797: Cisco WebEx Meetings Server information disclosure in admin server FQDN

CVE-2017-3797 · Severity: medium · CVSS 5.3 · Published 2017-01-26

Technologies: Cisco Webex Meetings Server. Vendors: Cisco.

Executive brief

Cisco WebEx Meetings Server is a private cloud solution for hosting online meetings and collaboration. A vulnerability in this server could allow an unauthorized person to see the internal web address (domain name) of the administration server. While this does not grant direct access to meeting data, it provides an attacker with technical details about the internal network structure that could be used to plan further attacks.

Technical details

An information disclosure vulnerability (CWE-200) exists in Cisco WebEx Meetings Server due to insufficient masking of sensitive data in HTTP responses. A remote, unauthenticated attacker can exploit this by sending specific HTTP requests to the affected system. Successful exploitation allows the attacker to retrieve the fully qualified domain name (FQDN) of the administration server. This vulnerability affects version 2.7; Cisco has released software updates to address the issue, and no workarounds are available.

Affected products

  • Cisco WebEx Meetings Server 2.7

Timeline

  • 2017-01-18: advisory: Initial Cisco advisory release
  • 2017-01-26: disclosed: NVD publication date

References

Related threats