5
CVSSv2

CVE-2015-4194

Published: 19/06/2015 Updated: 28/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether the username exists or corresponds to a privileged account, which allows remote malicious users to enumerate account names and obtain sensitive information via a series of requests, aka Bug ID CSCuf28861.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meeting center -

Vendor Advisories

A vulnerability in the web-based administrative interface of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to enumerate valid usernames and determine if the usernames have administrative privileges The vulnerability is due to a logic error in the handling of invalid usernames An attacker could exploit this vulnerabil ...