Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Multiple Cisco WebEx Products Cache Directory Read Vulnerability

Cisco-SA-20130502-CVE-2013-1231 · Medium · Published · Updated

A vulnerability in multiple Cisco WebEx products could allow an unauthenticated, remote attacker to read files from the cache directory. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by passing a crafted HTTP request to a WebEx node and read files from the cache directory. Cisco has confirmed the vulnerability in a security notice and software updates are available. To exploit the vulnerability, an attacker would likely need access to a trusted, internal network to send crafted HTTP requests to the targeted system. This access requirement may reduce the likelihood of a successful attack. Customers are advised to review the bug reports in the "Vendor Announcements" section for a current list of affected versions. Software updates are available for Cisco WebEx Meetings Server; however, at the time this alert was first published, software updates for Cisco WebEx Node for MCS were not available. Administrators are advised to contact the vendor regarding future updates and releases.

Cisco advisory · CSAF JSON

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to have network access.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2013-1231
Cisco Bug IDsCSCue36629, CSCue36664
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:U/RC:C
Base 5.0 AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C
Product Names From Source
Cisco WebEx Meetings Server, Cisco WebEx Node for MCS

Related Products

Product CVE Evidence
Cisco Webex Meetings CVE-2013-1231 Cisco OpenVuln
Cisco WebEx Node for MCS CVE-2013-1231 Cisco OpenVuln
Cisco WebEx Meetings Server CVE-2013-1231 Cisco OpenVuln