Cisco-SA-20140930-CVE-2014-3395

Cisco WebEx Meetings Server Arbitrary Download Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

A vulnerability in Cisco WebEx Meetings Server (Cisco WMS) could allow an unauthenticated, remote attacker to download arbitrary files to an affected device. The vulnerability is due to insufficient user-input validation. An attacker could exploit this vulnerability by submitting crafted URL requests to a vulnerable device. Cisco has confirmed the vulnerability in a security notice and released software updates. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.