We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2021-1410

Cisco Webex Meetings Unauthorized Distribution List Update Vulnerability



Assignercisco
Reserved2020-11-13
Published2024-11-18
Updated2024-11-18

Description

A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insufficient authorization enforcement for requests to update distribution lists. An attacker could exploit this vulnerability by sending a crafted request to the Webex Meetings interface to modify an existing distribution list. A successful exploit could allow the attacker to modify a distribution list that belongs to a user other than themselves.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.



MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/RL:X/RC:X/E:X

Product status

Default status
unknown

39.7.7
affected

39.9
affected

40.4.10
affected

39.6
affected

40.6.2
affected

39.8.2
affected

39.8.4
affected

40.1
affected

39.11
affected

39.7.4
affected

39.9.1
affected

40.4
affected

40.6
affected

39.7
affected

39.8
affected

39.8.3
affected

40.2
affected

39.10
affected

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-distupd-N87eB6Z3 (cisco-sa-webex-distupd-N87eB6Z3)

cve.org CVE-2021-1410

nvd.nist.gov CVE-2021-1410

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2021-1410
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.