Lucene search

K
ciscoCiscoCISCO-SA-20150115-CVE-2014-8032
HistoryJan 15, 2015 - 10:31 p.m.

Cisco WebEx Meetings Server Password Encryption Vulnerability

2015-01-1522:31:23
tools.cisco.com
17

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS

0.001

Percentile

50.2%

A vulnerability in the OutlookAction LI of Cisco WebEx Meetings Server could allow an authenticated, remote attacker to generate sensitive encrypted values.

The vulnerability is due to the return of a user’s encrypted password. An attacker could exploit this vulnerability by generating these sensitive values.

Cisco has confirmed the vulnerability in a security notice and has released software updates.

To exploit this vulnerability, an attacker requires authenticated access to the targeted system. Authenticated access may require the attacker to access trusted, internal networks. These requirements could limit the likelihood of a successful exploit.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscowebex_meetings_serverMatchany
OR
ciscowebex_meetings_serverMatchany
VendorProductVersionCPE
ciscowebex_meetings_serveranycpe:2.3:a:cisco:webex_meetings_server:any:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS

0.001

Percentile

50.2%

Related for CISCO-SA-20150115-CVE-2014-8032