Design Flaw in Cisco WebEx Meetings Server Exposes Sensitive Information
CVE-2018-0109
2.7LOW
Summary
A design flaw in Cisco WebEx Meetings Server permits an authenticated remote attacker to exploit the system and gain unauthorized access to sensitive information. This vulnerability allows an attacker already authenticated as a root user to retrieve shared secrets, which could facilitate subsequent reconnaissance attacks. By exploiting this flaw, the attacker could obtain critical application-related data, enhancing the risk of further exploitation. The issue is tracked under Cisco Bug ID CSCvg42664, and relevant resources can be found through Cisco's security advisory and other vulnerability databases.
Affected Version(s)
Cisco WebEx Meetings Server Cisco WebEx Meetings Server
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved