Insufficient Entropy in Cisco WebEx Meetings Server Enables Unauthorized Access
CVE-2014-0691
7.3HIGH
Summary
The Cisco WebEx Meetings Server prior to version 1.1 has a vulnerability that stems from the use of meeting IDs with inadequate entropy levels. This flaw enables remote attackers to potentially bypass authentication measures, allowing them to join meetings without proper authorization or password protection. The vulnerability poses a threat as it can facilitate unauthorized access to sensitive meetings, impacting both data confidentiality and user privacy.
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved