Cisco WebEx Meeting Server CVE-2014-3286 User Enumeration Vulnerability
BID:67922
Info
Cisco WebEx Meeting Server CVE-2014-3286 User Enumeration Vulnerability
| Bugtraq ID: | 67922 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-3286 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2014 12:00AM |
| Updated: | Jul 28 2014 12:28AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco WebEx Meeting Server CVE-2014-3286 User Enumeration Vulnerability
Cisco WebEx Meeting Server is prone to a user-enumeration vulnerability.
An attacker may leverage this issue to harvest valid user accounts, which may aid in brute-force attacks.
This issue being tracked by Cisco Bug IDs CSCuj81685, CSCuj81688, CSCuj81665, CSCuj81744, CSCuj81661, and CSCuj81655.
Cisco WebEx Meeting Server is prone to a user-enumeration vulnerability.
An attacker may leverage this issue to harvest valid user accounts, which may aid in brute-force attacks.
This issue being tracked by Cisco Bug IDs CSCuj81685, CSCuj81688, CSCuj81665, CSCuj81744, CSCuj81661, and CSCuj81655.
Exploit / POC
Cisco WebEx Meeting Server CVE-2014-3286 User Enumeration Vulnerability
An attacker can exploit this issue by supplying the device with specially crafted URL requests.
An attacker can exploit this issue by supplying the device with specially crafted URL requests.
Solution / Fix
Cisco WebEx Meeting Server CVE-2014-3286 User Enumeration Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco WebEx Meeting Server CVE-2014-3286 User Enumeration Vulnerability
References:
References:
- Cisco Homepage (Cisco )