Cisco Unified MeetingPlace Web Conferencing CVE-2013-3438 Security Bypass Vulnerability
BID:61417
Info
Cisco Unified MeetingPlace Web Conferencing CVE-2013-3438 Security Bypass Vulnerability
| Bugtraq ID: | 61417 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3438 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2013 12:00AM |
| Updated: | Jul 24 2013 12:00AM |
| Credit: | Cisco |
| Vulnerable: |
Cisco Unified MeetingPlace Web Conferencing 7.0 Cisco Unified MeetingPlace Web Conferencing 6.0 |
| Not Vulnerable: | |
Discussion
Cisco Unified MeetingPlace Web Conferencing CVE-2013-3438 Security Bypass Vulnerability
Cisco Unified MeetingPlace Web Conferencing is prone to a security-bypass vulnerability.
Exploiting this issue could allow an attacker to bypass certain security restrictions and obtain unauthorized access to sensitive information on the affected device. This may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCuh86385.
Cisco Unified MeetingPlace Web Conferencing versions 8.5 SR2(4) and prior are vulnerable; other versions may also be affected.
Cisco Unified MeetingPlace Web Conferencing is prone to a security-bypass vulnerability.
Exploiting this issue could allow an attacker to bypass certain security restrictions and obtain unauthorized access to sensitive information on the affected device. This may aid in further attacks.
This issue is being tracked by Cisco Bug ID CSCuh86385.
Cisco Unified MeetingPlace Web Conferencing versions 8.5 SR2(4) and prior are vulnerable; other versions may also be affected.
Exploit / POC
Cisco Unified MeetingPlace Web Conferencing CVE-2013-3438 Security Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Cisco Unified MeetingPlace Web Conferencing CVE-2013-3438 Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Unified MeetingPlace Web Conferencing CVE-2013-3438 Security Bypass Vulnerability
References:
References: