5
CVSSv2

CVE-2017-6651

Published: 16/05/2017 Updated: 08/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote malicious users to gain information that could allow them to access scheduled customer meetings. The vulnerability is due to an incomplete configuration of the robots.txt file on customer-hosted WebEx solutions and occurs when the Short URL functionality is not activated. All releases of Cisco WebEx Meetings Server later than release 2.5MR4 provide this functionality. An attacker could exploit this vulnerability via an exposed parameter to search for indexed meeting information. A successful exploit could allow the malicious user to obtain scheduled meeting information and potentially allow the malicious user to attend scheduled, customer meetings. This vulnerability affects the following releases of Cisco WebEx Meetings Server: 2.5, 2.6, 2.7, 2.8. Cisco Bug IDs: CSCve25950.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco webex meetings server 2.6.1.39

cisco webex meetings server 2.5_mr6

cisco webex meetings server 2.5_mr5

cisco webex meetings server 2.6_mr1

cisco webex meetings server 2.7_mr1

cisco webex meetings server 2.6_mr2

cisco webex meetings server 2.5.99.2

cisco webex meetings server 2.5.1.29

cisco webex meetings server 2.5_mr1

cisco webex meetings server 2.5_base

cisco webex meetings server 2.5_mr2

cisco webex meetings server 2.6_mr3

cisco webex meetings server 2.7_base

cisco webex meetings server 2.7_mr2

cisco webex meetings server 2.6.0

cisco webex meetings server 2.7.1

cisco webex meetings server 2.5.1.5

cisco webex meetings server 2.5_mr3

cisco webex meetings server 2.8_base

cisco webex meetings server 2.5_mr4

Vendor Advisories

A vulnerability in Cisco WebEx Meetings Server could allow unauthenticated, remote attackers to gain information that could allow them to access scheduled customer meetings The vulnerability is due to an incomplete configuration of the robotstxt file on customer-hosted WebEx solutions and occurs when the Short URL functionality is not activated ...