A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) prior to 2.0.6 and Acano Server prior to 1.8.18 and 1.9.x prior to 1.9.6 could allow an unauthenticated, remote malicious user to masquerade as a legitimate user. This vulnerability is due to the XMPP service incorrectly processing a deprecated authentication scheme. A successful exploit could allow an malicious user to access the system as another user.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cisco meeting server 2.0.1 |
||
cisco meeting server 2.0.4 |
||
cisco meeting server 2.0.0 |
||
cisco meeting server 1.8.15 |
||
cisco meeting server 1.8_base |
||
cisco meeting server 2.0.3 |
||
cisco meeting server 2.0.5 |
||
cisco meeting server 1.9.0 |
||
cisco meeting server 1.9.2 |