Cross-Site Request Forgery Vulnerability in Cisco WebEx Meetings Server
CVE-2017-3794

8.8HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
26 January 2017

What is CVE-2017-3794?

A security flaw in Cisco WebEx Meetings Server allows an unauthenticated remote attacker to initiate a cross-site request forgery (CSRF) attack targeting an administrative user. This could lead to unauthorized actions being executed on behalf of the admin without their consent. The affected version is 2.6, and it is crucial to upgrade to the fixed version 2.7.1.12 to mitigate the risks associated with this vulnerability. For more details, refer to Cisco's security advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cisco WebEx Meetings Server 2.6 Cisco WebEx Meetings Server 2.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.