CVE Vulnerabilities

CVE-2021-1517

Protection Mechanism Failure

Published: Jun 04, 2021 | Modified: Nov 07, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the multimedia viewer feature. An attacker could exploit this vulnerability by sharing a file through the multimedia viewer feature. A successful exploit could allow the attacker to bypass security protections and prevent warning dialogs from appearing before files are offered to other users.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

Name Vendor Start Version End Version
Webex_meetings_online Cisco 41.3.5 (including) 41.3.5 (including)
Webex_meetings_server Cisco * 3.0 (excluding)
Webex_meetings_server Cisco 3.0 (including) 3.0 (including)
Webex_meetings_server Cisco 3.0-maintenance_release1 (including) 3.0-maintenance_release1 (including)
Webex_meetings_server Cisco 3.0-maintenance_release2 (including) 3.0-maintenance_release2 (including)
Webex_meetings_server Cisco 3.0-maintenance_release3 (including) 3.0-maintenance_release3 (including)
Webex_meetings_server Cisco 4.0 (including) 4.0 (including)
Webex_meetings_server Cisco 4.0-maintenance_release1 (including) 4.0-maintenance_release1 (including)
Webex_meetings_server Cisco 4.0-maintenance_release2 (including) 4.0-maintenance_release2 (including)
Webex_meetings_server Cisco 4.0-maintenance_release3 (including) 4.0-maintenance_release3 (including)
Webex_meetings_server Cisco 4.0-maintenance_release3_security_patch3 (including) 4.0-maintenance_release3_security_patch3 (including)
Webex_meetings_server Cisco 4.0-maintenance_release3_security_patch4 (including) 4.0-maintenance_release3_security_patch4 (including)

References