6.4
CVSSv2

CVE-2015-4209

Published: 23/06/2015 Updated: 28/12/2016
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote malicious users to obtain sensitive information by obtaining a list of all meetings and then sending a calendar request for each one, aka Bug ID CSCur23913.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meeting center -

Vendor Advisories

A vulnerability in Cisco WebEx Meetings could allow an unauthenticated, remote attacker to access and download calendar files without authorization The vulnerability is due to inconsistent authorization checks An attacker could exploit this vulnerability by enumerating scheduled meetings and downloading the host calendar for each meeting Cis ...