CVE-2021-1517
Summary
| CVE | CVE-2021-1517 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-04 17:15:00 UTC |
| Updated | 2023-11-07 03:28:00 UTC |
| Description | A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the multimedia viewer feature. An attacker could exploit this vulnerability by sharing a file through the multimedia viewer feature. A successful exploit could allow the attacker to bypass security protections and prevent warning dialogs from appearing before files are offered to other users. |
Risk And Classification
Problem Types: CWE-693
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Webex Meetings Online | 41.3.5 | All | All | All |
| Application | Cisco | Webex Meetings Server | All | All | All | All |
| Application | Cisco | Webex Meetings Server | 3.0 | - | All | All |
| Application | Cisco | Webex Meetings Server | 3.0 | maintenance_release1 | All | All |
| Application | Cisco | Webex Meetings Server | 3.0 | maintenance_release2 | All | All |
| Application | Cisco | Webex Meetings Server | 3.0 | maintenance_release3 | All | All |
| Application | Cisco | Webex Meetings Server | 4.0 | - | All | All |
| Application | Cisco | Webex Meetings Server | 4.0 | maintenance_release1 | All | All |
| Application | Cisco | Webex Meetings Server | 4.0 | maintenance_release2 | All | All |
| Application | Cisco | Webex Meetings Server | 4.0 | maintenance_release3 | All | All |
| Application | Cisco | Webex Meetings Server | 4.0 | maintenance_release3_security_patch3 | All | All |
| Application | Cisco | Webex Meetings Server | 4.0 | maintenance_release3_security_patch4 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Webex Meetings and Webex Meetings Server Multimedia Sharing Security Bypass Vulnerability | CISCO | tools.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.