CVE Vulnerabilities

CVE-2021-1517

Protection Mechanism Failure

Published: Jun 04, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the multimedia viewer feature. An attacker could exploit this vulnerability by sharing a file through the multimedia viewer feature. A successful exploit could allow the attacker to bypass security protections and prevent warning dialogs from appearing before files are offered to other users.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

NameVendorStart VersionEnd Version
Webex_meetings_onlineCisco41.3.5 (including)41.3.5 (including)
Webex_meetings_serverCisco*3.0 (excluding)
Webex_meetings_serverCisco3.0 (including)3.0 (including)
Webex_meetings_serverCisco3.0-maintenance_release1 (including)3.0-maintenance_release1 (including)
Webex_meetings_serverCisco3.0-maintenance_release2 (including)3.0-maintenance_release2 (including)
Webex_meetings_serverCisco3.0-maintenance_release3 (including)3.0-maintenance_release3 (including)
Webex_meetings_serverCisco4.0 (including)4.0 (including)
Webex_meetings_serverCisco4.0-maintenance_release1 (including)4.0-maintenance_release1 (including)
Webex_meetings_serverCisco4.0-maintenance_release2 (including)4.0-maintenance_release2 (including)
Webex_meetings_serverCisco4.0-maintenance_release3 (including)4.0-maintenance_release3 (including)
Webex_meetings_serverCisco4.0-maintenance_release3_security_patch3 (including)4.0-maintenance_release3_security_patch3 (including)
Webex_meetings_serverCisco4.0-maintenance_release3_security_patch4 (including)4.0-maintenance_release3_security_patch4 (including)

References