Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

CVE-2021-1372

CVE information

Published

3 years ago

Last Modified

5 months ago

CVSSv2.0 Severity

Low

CVSSv3.1 Severity

Medium

Impact Analysis

Description

A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. This vulnerability is due to the unsafe usage of shared memory by the affected software. An attacker with permissions to view system memory could exploit this vulnerability by running an application on the local system that is designed to read shared memory. A successful exploit could allow the attacker to retrieve sensitive information from the shared memory, including usernames, meeting information, or authentication tokens. Note: To exploit this vulnerability, an attacker must have valid credentials on a Microsoft Windows end-user system and must log in after another user has already authenticated with Webex on the same end-user system..

CVSSv2.0 Score

Severity
Low
Base Score
2.1/10
Exploit Score
3.9/10
Access Vector
Local
Access Complexity
Low
Authentication Required
None
Impact Score
2.9/10
Confidentiality Impact
Partial
Availability Impact
None
Integrity Impact
None

CVSSv3.1 Score

Severity
Medium
Base Score
5.5/10
Exploit Score
1.8/10
Access Vector
Local
Access Complexity
Low
Privileges Required
Low
Impact Score
3.6/10
Confidentiality Impact
High
Availability Impact
None
Integrity Impact
None
Scope
Unchanged
User Interaction
None

Products Affected

CPE Affected Vulnerable Excluding Edit
cpe:2.3:a:cisco:webex_meetings_server:*:*:*:*:*:*:*:*
  Yes
- 4.0
cpe:2.3:a:cisco:webex_meetings_server:4.0:-:*:*:*:*:*:*
  Yes
- -
cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_releas
  Yes
- -
cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_releas
  Yes
- -
cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_releas
  Yes
- -
cpe:2.3:a:cisco:webex_meetings_server:4.0:maintenance_releas
  Yes
- -
cpe:2.3:a:cisco:webex_meetings:*:*:*:*:latest_channel:*:*:*
  Yes
- 40.10
cpe:2.3:a:cisco:webex_meetings:*:*:*:*:slow_channel:*:*:*
  Yes
- 40.6