A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host key. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Webex Meetings Server site. A successful exploit would require the attacker to have access to join a Webex meeting, including applicable meeting join links and passwords. A successful exploit could allow the attacker to acquire or take over the host role for a meeting.
References
Link | Resource |
---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-brutef-hostkey-FWRMxVF | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Jan 2021, 16:12
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release2:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings:*:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release3:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release1:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings_server:*:*:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings_server:4.0:-:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_release3:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_release1:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings_server:3.0:maintenance_release4:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings_server:3.0:-:*:*:*:*:*:* cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_release2:*:*:*:*:*:* |
|
References | (CISCO) https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-brutef-hostkey-FWRMxVF - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 5.5
v3 : 5.4 |
CWE | CWE-307 |
13 Jan 2021, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-01-13 22:15
Updated : 2024-04-11 13:25
NVD link : CVE-2021-1311
Mitre link : CVE-2021-1311
CVE.ORG link : CVE-2021-1311
JSON object : View
Products Affected
cisco
- webex_meetings_server
- webex_meetings
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts