VendorsCiscowebex_meetings_serverall versions
Vulnerabilities

Cisco Webex Meetings Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

136CVEs
CVE-2019-1924
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2019-08-07 · Modified
9.3EPSS 0.015
CVE-2019-1929
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2019-08-07 · Modified
9.3EPSS 0.015
CVE-2019-1928
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2019-08-07 · Modified
9.3EPSS 0.015
CVE-2019-1925
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2019-08-07 · Modified
9.3EPSS 0.015
CVE-2019-1641
Cisco Webex Network Recording Player Arbitrary Code Execution Vulnerabilities
Published 2019-01-23 · Modified
9.3EPSS 0.014
CVE-2019-15286
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2019-11-26 · Modified
9.3EPSS 0.014
CVE-2019-15284
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
Published 2019-11-26 · Modified
9.3EPSS 0.014
CVE-2020-3419
Cisco Webex Meetings and Cisco Webex Meetings Server Ghost Join Vulnerability
Published 2020-11-18 · Modified
9.1EPSS 0.018
CVE-2015-0589
The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands with root privileges via unspecified fields, aka Bug ID CSCuj40460.
Published 2015-02-07 · Modified
9.0EPSS 0.034
CVE-2018-0112
A vulnerability in Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability is due to insufficient input validation by the Cisco WebEx clients. An attacker could exploit this vulnerability by providing meeting attendees with a malicious Flash (.swf) file via the file-sharing capabilities of the client. Exploitation of this vulnerability could allow arbitrary code execution on the system of a targeted user. This affects the clients installed by customers when accessing a WebEx meeting. The following client builds of Cisco WebEx Business Suite (WBS30, WBS31, and WBS32), Cisco WebEx Meetings, and Cisco WebEx Meetings Server are impacted: Cisco WebEx Business Suite (WBS31) client builds prior to T31.23.2, Cisco WebEx Business Suite (WBS32) client builds prior to T32.10, Cisco WebEx Meetings with client builds prior to T32.10, Cisco WebEx Meetings Server builds prior to 2.8 MR2. Cisco Bug IDs: CSCvg19384, CSCvi10746.
Published 2018-04-19 · Modified
9.0EPSS 0.026
CVE-2016-1446
SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.
Published 2016-07-15 · Modified
8.8EPSS 0.018
CVE-2017-3794
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user. More Information: CSCuz03317. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.12.
Published 2017-01-26 · Modified
8.8EPSS 0.011
CVE-2016-1448
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuy92706.
Published 2016-07-17 · Modified
8.8EPSS 0.009
CVE-2017-12293
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient limitations on the number of connections that can be made to the affected software. An attacker could exploit this vulnerability by opening multiple connections to the server and exhausting server resources. A successful exploit could cause the server to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf41006.
Published 2017-10-19 · Modified
8.6EPSS 0.023
CVE-2018-0110
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote support account even after it has been disabled via the web application. The vulnerability is due to a design flaw in Cisco WebEx Meetings Server, which would not disable access to specifically configured user accounts, even after access had been disabled in the web application. An attacker could exploit this vulnerability by connecting to the remote support account, even after it had been disabled at the web application level. An exploit could allow the attacker to modify server configuration and gain access to customer data. Cisco Bug IDs: CSCvg46741.
Published 2018-01-18 · Modified
8.1EPSS 0.014
CVE-2016-1483
Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation component of an unspecified service, aka Bug ID CSCuy92704.
Published 2016-09-19 · Modified
7.8EPSS 0.019
CVE-2018-15409
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
7.8EPSS 0.019
CVE-2021-1502
Cisco Webex Network Recording Player and Webex Player Memory Corruption Vulnerability
Published 2021-06-04 · Modified
7.8EPSS 0.011
CVE-2021-1503
Cisco Webex Network Recording Player and Webex Player Memory Corruption Vulnerability
Published 2021-06-04 · Modified
7.8EPSS 0.010
CVE-2019-1771
Cisco Webex Network Recording Player Arbitrary Code Execution Vulnerability
Published 2019-05-15 · Modified
7.8EPSS 0.005
CVE-2021-1536
Cisco Webex Meetings, Webex Network Recording Player, and Webex Teams DLL Injection Vulnerability
Published 2021-06-04 · Modified
7.8EPSS 0.003
CVE-2019-1868
Cisco Webex Meetings Server Information Disclosure Vulnerability
Published 2019-06-05 · Modified
7.5EPSS 0.021
CVE-2017-6651
A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that could allow them to access scheduled customer meetings. The vulnerability is due to an incomplete configuration of the robots.txt file on customer-hosted WebEx solutions and occurs when the Short URL functionality is not activated. All releases of Cisco WebEx Meetings Server later than release 2.5MR4 provide this functionality. An attacker could exploit this vulnerability via an exposed parameter to search for indexed meeting information. A successful exploit could allow the attacker to obtain scheduled meeting information and potentially allow the attacker to attend scheduled, customer meetings. This vulnerability affects the following releases of Cisco WebEx Meetings Server: 2.5, 2.6, 2.7, 2.8. Cisco Bug IDs: CSCve25950.
Published 2017-05-16 · Modified
7.5EPSS 0.020
CVE-2016-1484
Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspecified vectors, aka Bug ID CSCuy92724.
Published 2016-08-23 · Modified
7.5EPSS 0.016
CVE-2016-1450
Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, aka Bug ID CSCuy92715.
Published 2016-07-15 · Modified
7.5EPSS 0.013
CVE-2016-1389
Open redirect vulnerability in Cisco WebEx Meetings Server (CWMS) 2.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuy44695.
Published 2016-04-28 · Modified
7.4EPSS 0.013
CVE-2018-0422
A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. The vulnerability is due to folder permissions that grant a user the permission to read, write, and execute files in the Webex folders. An attacker could exploit this vulnerability to write malicious files to the Webex client directory, affecting all other users of the targeted device. A successful exploit could allow a user to execute commands with elevated privileges. Attacks on single-user systems are less likely to occur, as the attack must be carried out by the user on the user's own system. Multiuser systems have a higher risk of exploitation because folder permissions have an impact on all users of the device. For an attacker to exploit this vulnerability successfully, a second user must execute the locally installed malicious file to allow remote code execution to occur.
Published 2018-10-05 · Modified
7.3EPSS 0.011
CVE-2014-0691
Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643.
Published 2017-10-24 · Modified
7.3EPSS 0.010
CVE-2018-15431
Cisco Webex Network Recording Player and Cisco Webex Player Remote Code Execution Vulnerabilities
Published 2018-10-05 · Modified
7.3EPSS 0.005
CVE-2017-3796
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute predetermined shell commands on other hosts. More Information: CSCuz03353. Known Affected Releases: 2.6.
Published 2017-01-26 · Modified
7.2EPSS 0.019
CVE-2014-3305
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735.
Published 2014-07-26 · Modified
6.8EPSS 0.013
CVE-2013-5529
The deployment module in the server in Cisco WebEx Meeting Center does not properly validate the passphrase, which allows remote attackers to launch a deployment or cause a denial of service (deployment interruption) via a direct request, aka Bug ID CSCuf52200.
Published 2013-10-16 · Modified
6.8EPSS 0.012
CVE-2015-4281
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.5 MR1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCus56150 and CSCus56146.
Published 2015-07-22 · Modified
6.8EPSS 0.010
CVE-2015-0596
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj67163.
Published 2015-02-02 · Modified
6.8EPSS 0.009
CVE-2014-8031
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456.
Published 2015-01-09 · Modified
6.8EPSS 0.006
CVE-2014-2186
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj81777.
Published 2014-04-30 · Modified
6.8EPSS 0.006
CVE-2015-4276
Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a crafted command parameter, aka Bug ID CSCus56138.
Published 2015-07-16 · Modified
6.5EPSS 0.025
CVE-2020-3471
Cisco Webex Meetings and Cisco Webex Meetings Server Unauthorized Audio Information Exposure Vulnerability
Published 2020-11-18 · Modified
6.5EPSS 0.018
CVE-2017-12359
A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (.arf) files could allow an attacker to execute arbitrary code on a system. An attacker could exploit this vulnerability by providing a user with a malicious .arf file via email or URL and convincing the user to launch the file. Exploitation of this vulnerability could allow arbitrary code execution on the system of the targeted user. This vulnerability affects Cisco WebEx Business Suite meeting sites, Cisco WebEx Meetings sites, Cisco WebEx Meetings Server, and Cisco WebEx ARF players. Cisco Bug IDs: CSCve10729, CSCve10771, CSCve10779, CSCve11521, CSCve11543.
Published 2017-11-30 · Modified
6.5EPSS 0.017
CVE-2017-3880
An Authentication Bypass vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access limited meeting information on the Cisco WebEx Meetings Server. More Information: CSCvd50728. Known Affected Releases: 2.6 2.7 2.8 CWMS-2.5MR1 Orion1.1.2.patch T29_orion_merge.
Published 2017-03-17 · Modified
6.5EPSS 0.015
← Prev2 / 4Next →