Executive brief
Cisco WebEx Meeting Center, a popular online meeting and video conferencing platform, was found to have a security flaw that allows attackers to redirect users to malicious websites. By sending a specially crafted link, an attacker can trick a user into visiting a fraudulent site that may be used for phishing or malware delivery. This type of attack relies on the user's trust in the legitimate WebEx domain to hide the destination of the malicious link.
Technical details
An open redirect vulnerability (CWE-601) exists in Cisco WebEx Meeting Center due to insufficient validation of input within a specific URL parameter. An unauthenticated remote attacker can exploit this by crafting a URL that includes a malicious destination in the affected parameter. If a user clicks the link, they are redirected from the legitimate Cisco WebEx domain to an untrusted external site. While the vulnerability itself does not allow for direct data theft, it is a primary vector for phishing campaigns. Cisco has released software updates and provided a workaround involving the 'Enforce BACKURL Domain Names' setting in the administrator panel.
Affected products
- Cisco WebEx Meeting Center T28.1, WBS28
Timeline
- 2017-01-18: advisory: Initial Cisco advisory published
- 2017-01-26: disclosed: NVD publication date