HTTP Cache Poisoning Vulnerability in Cisco Webex Meetings
CVE-2025-20255

4.3MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
21 May 2025

Badges

👾 Exploit Exists

What is CVE-2025-20255?

A vulnerability exists in the client join services of Cisco Webex Meetings, potentially allowing unauthenticated remote attackers to exploit cached HTTP responses. This vulnerability arises from inadequate handling of malicious HTTP requests directed at the join service, enabling an attacker to perform HTTP cache poisoning. By successfully manipulating the stored HTTP responses within the service, attackers could force Webex Meetings to deliver incorrect information to clients, leading to unreliable service operations.

Affected Version(s)

Cisco Webex Meetings

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20255 : HTTP Cache Poisoning Vulnerability in Cisco Webex Meetings