5
CVSSv2

CVE-2014-8034

Published: 15/01/2015 Updated: 08/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote malicious users to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meetings server 1.5

Vendor Advisories

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to guess valid user accounts on the targeted system The vulnerability exists because the affected software fails to refresh the CAPTCHA on the login page An attacker could exploit this vulnerability by conducting unlimited user account guessing attempt ...