4.3
CVSSv2

CVE-2014-3310

Published: 10/07/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not verify that a requested file was an offered file, which allows remote malicious users to read arbitrary files via a modified request, aka Bug IDs CSCup62442 and CSCup58463.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meeting center -

cisco webex meetings server -

Vendor Advisories

A vulnerability in the File Transfer functionality of the Cisco WebEx Meetings client could allow an unauthenticated, remote attacker to access arbitrary files on another user's computer also running the Cisco WebEx Meetings client The vulnerability exists because the affected software does not properly verify that the file offered by a sending c ...