Cisco WebEx Error Message Information Disclosure Vulnerability

Cisco-SA-20130802-CVE-2013-3425 · Medium · Published · Updated

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

A vulnerability in Cisco WebEx could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to improper error messages displayed by the affected software when handling requests to view another user's files. An attacker could exploit this vulnerability by submitting crafted security parameter index (SPI) calls to the affected software. Successful exploitation could allow attackers to determine the existence of files they are not authorized to access. This information could be used to launch additional attacks. Cisco has confirmed this vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must authenticate to a targeted device. This access requirement decreases the likelihood of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to have network access.

Administrators are advised to allow only privileged users to access administration or management systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2013-3425
Cisco Bug IDsCSCuc35965
CVSS ScoreBase 4.0
Base 4.0 AV:N/AC:L/Au:S/C:P/I:N/A:N/E:F/RL:OF/RC:C

Products with public affected evidence