CVE-2023-20180
Summary
| CVE | CVE-2023-20180 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-07 20:15:00 UTC |
| Updated | 2024-01-25 17:15:00 UTC |
| Description | A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web interface on an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions. These actions could include joining meetings and scheduling training sessions. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Webex Meetings | 39.10 | All | All | All |
| Application | Cisco | Webex Meetings | 39.11 | All | All | All |
| Application | Cisco | Webex Meetings | 39.6 | All | All | All |
| Application | Cisco | Webex Meetings | 39.7 | All | All | All |
| Application | Cisco | Webex Meetings | 39.7.4 | All | All | All |
| Application | Cisco | Webex Meetings | 39.7.7 | All | All | All |
| Application | Cisco | Webex Meetings | 39.8 | All | All | All |
| Application | Cisco | Webex Meetings | 39.8.2 | All | All | All |
| Application | Cisco | Webex Meetings | 39.8.3 | All | All | All |
| Application | Cisco | Webex Meetings | 39.8.4 | All | All | All |
| Application | Cisco | Webex Meetings | 39.9 | All | All | All |
| Application | Cisco | Webex Meetings | 39.9.1 | All | All | All |
| Application | Cisco | Webex Meetings | 40.1 | All | All | All |
| Application | Cisco | Webex Meetings | 40.2 | All | All | All |
| Application | Cisco | Webex Meetings | 40.4 | All | All | All |
| Application | Cisco | Webex Meetings | 40.4.10 | All | All | All |
| Application | Cisco | Webex Meetings | 40.6 | All | All | All |
| Application | Cisco | Webex Meetings | 40.6.2 | All | All | All |
| Application | Cisco | Webex Meetings | 42.10 | All | All | All |
| Application | Cisco | Webex Meetings | 42.11 | All | All | All |
| Application | Cisco | Webex Meetings | 42.12 | All | All | All |
| Application | Cisco | Webex Meetings | 42.6 | All | All | All |
| Application | Cisco | Webex Meetings | 42.7 | All | All | All |
| Application | Cisco | Webex Meetings | 42.8 | All | All | All |
| Application | Cisco | Webex Meetings | 42.9 | All | All | All |
| Application | Cisco | Webex Meetings | 43.1 | All | All | All |
| Application | Cisco | Webex Meetings | 43.2 | All | All | All |
| Application | Cisco | Webex Meetings | 43.3 | All | All | All |
| Application | Cisco | Webex Meetings | 43.4 | All | All | All |
| Application | Cisco | Webex Meetings | 43.4.1 | All | All | All |
| Application | Cisco | Webex Meetings | 43.4.2 | All | All | All |
| Application | Cisco | Webex Meetings | 43.5.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Webex Meetings Web UI Vulnerabilities | MISC | sec.cloudapps.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.