Cisco WebEx One-Click Client Password Encryption Information Disclosure Vulnerability
BID:61304
Info
Cisco WebEx One-Click Client Password Encryption Information Disclosure Vulnerability
| Bugtraq ID: | 61304 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 09 2013 12:00AM |
| Updated: | Jul 09 2013 12:00AM |
| Credit: | Brad Antoniewicz of Open Security Research |
| Vulnerable: |
Cisco WebEx (Windows) 27.10 Cisco WebEx (Windows) 26.49.32 Cisco WebEx (Windows) T27 SP28 Cisco WebEx (Windows) T27 SP25 EP3 Cisco WebEx (Windows) T27 SP23 Cisco WebEx (Windows) T27 SP21 EP9 Cisco WebEx (Windows) T27 SP11 EP23 Cisco WebEx (Windows) T27 LD SP32 CP1 Cisco WebEx (Windows) T27 LD SP32 Cisco WebEx (Windows) T27 LC SP25 EP9 Cisco WebEx (Windows) T27 LC SP25 EP10 Cisco WebEx (Windows) T27 LB SP21 EP10 Cisco WebEx (Windows) T27 L SP11 EP26 Cisco WebEx (Windows) T27 FR20 Cisco WebEx (Windows) T26 SP49 EP40 Cisco WebEx (Windows) 3.26 Cisco WebEx (Windows) 28.4 Cisco WebEx (Windows) 28.1.0 Cisco WebEx (Windows) 27LC SP22 Cisco WebEx (Windows) 27LB SP21 EP3 Cisco WebEx (Windows) 27.32.2 Cisco WebEx (Windows) 27.32.10 Cisco WebEx (Windows) 27.25.11 Cisco WebEx (Windows) 27.00 Cisco WebEx (Windows) 26.00 |
| Not Vulnerable: | |
Discussion
Cisco WebEx One-Click Client Password Encryption Information Disclosure Vulnerability
Cisco WebEx One-Click Client is prone to an information disclosure vulnerability.
Successful exploits may allow an attacker to disclose sensitive information such as stored passwords; this may aid in further attacks.
Cisco WebEx One-Click Client is prone to an information disclosure vulnerability.
Successful exploits may allow an attacker to disclose sensitive information such as stored passwords; this may aid in further attacks.
Exploit / POC
Cisco WebEx One-Click Client Password Encryption Information Disclosure Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Cisco WebEx One-Click Client Password Encryption Information Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Cisco WebEx One-Click Client Password Encryption Information Disclosure Vulnerability
References:
References:
- Cisco WebEx Social HomePage (Cisco)
- OpenSecurityResearch/onedecrypt (Open Security)
- Quick Reversing - WebEx One-Click Password Storage (Open Security)