CVE-2017-12365
CVE-2017-12365
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
30 Nov 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information. The vulnerability is due to a design flaw in the product. An attacker could execute a query on an Event Center site to view scheduled meetings. A successful query would show both listed and unlisted meetings in the displayed information. An attacker could use this information to attend meetings that are not available for their attendance. Cisco Bug IDs: CSCvg33629.
Affected products
n/a · Cisco WebEx Event CenterWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →