QID 316676

Date Published: 2021-05-05

QID 316676: Cisco Meetings App Missing TURN Server Credentials Expiration Vulnerability(cisco-sa-cma-turn-crdls-RHjSzKXn)

A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system.

QID Detection Logic (Authenticated):
This checks for vulnerable version of Cisco Meetings App.

An exploit could allow the attacker to obtain the TURN server credentials, which the attacker could use to place audio/video calls and forward packets through the configured TURN server.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-cma-turn-crdls-RHjSzKXn for more information.

    CVEs related to QID 316676

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-cma-turn-crdls-RHjSzKXn URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cma-turn-crdls-RHjSzKXn