SB2020012701 - Improper access control in Cisco Webex Meetings Suite and Cisco Webex Meetings Online



SB2020012701 - Improper access control in Cisco Webex Meetings Suite and Cisco Webex Meetings Online

Published: January 27, 2020

Security Bulletin ID SB2020012701
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2020-3142)

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to unintended meeting information exposure in a specific meeting join flow for mobile applications. A remote attacker can join the password-protected meeting without providing the meeting password.

This vulnerability can be exploited by accessing a known meeting ID or meeting URL from the mobile device’s web browser. The browser will then request to launch the device’s Webex mobile application. The unauthorized attendee will be visible in the attendee list of the meeting as a mobile attendee.


Remediation

Install update from vendor's website.