Lucene search

K
ciscoCiscoCISCO-SA-20140710-CVE-2014-3310
HistoryJul 10, 2014 - 3:29 p.m.

Cisco WebEx Meetings Client Arbitrary File Download Vulnerability

2014-07-1015:29:11
tools.cisco.com
18

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

70.6%

A vulnerability in the File Transfer functionality of the Cisco WebEx Meetings client could allow an
unauthenticated, remote attacker to access arbitrary files on another
user’s computer also running the Cisco WebEx Meetings client.

The vulnerability exists because the affected software does not properly verify that the file offered by a sending client is the same as the file requested by the receiving client. An attacker could exploit
this vulnerability by using a modified Cisco WebEx Meetings client.

Cisco has confirmed the vulnerability in a security notice and released software updates.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscowebex_meeting_centerMatchany
OR
ciscowebex_meetings_serverMatchany
OR
ciscowebex_meeting_centerMatchany
OR
ciscowebex_meetings_serverMatchany
VendorProductVersionCPE
ciscowebex_meeting_centeranycpe:2.3:a:cisco:webex_meeting_center:any:*:*:*:*:*:*:*
ciscowebex_meetings_serveranycpe:2.3:a:cisco:webex_meetings_server:any:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

70.6%

Related for CISCO-SA-20140710-CVE-2014-3310