ID

VAR-201701-0720


CVE

CVE-2017-3794


TITLE

Cisco WebEx Meetings Server Vulnerable to cross-site request forgery

Trust: 0.8

sources: JVNDB: JVNDB-2017-001380

DESCRIPTION

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user. More Information: CSCuz03317. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.12. An attacker can exploit this issue to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible. This issue is being tracked by Cisco Bug ID CSCuz03317. Cisco WebEx Meetings Server (CWMS) is a set of multi-functional conference solutions including audio, video and Web conference in Cisco's WebEx conference solution

Trust: 2.07

sources: NVD: CVE-2017-3794 // JVNDB: JVNDB-2017-001380 // BID: 95635 // VULHUB: VHN-111997 // VULMON: CVE-2017-3794

AFFECTED PRODUCTS

vendor:ciscomodel:webex meetings serverscope:eqversion:2.6.0

Trust: 2.4

vendor:ciscomodel:webex meetings serverscope:eqversion:0

Trust: 0.3

sources: BID: 95635 // JVNDB: JVNDB-2017-001380 // CNNVD: CNNVD-201701-787 // NVD: CVE-2017-3794

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-3794
value: HIGH

Trust: 1.0

NVD: CVE-2017-3794
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201701-787
value: MEDIUM

Trust: 0.6

VULHUB: VHN-111997
value: MEDIUM

Trust: 0.1

VULMON: CVE-2017-3794
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-3794
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-111997
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-3794
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-111997 // VULMON: CVE-2017-3794 // JVNDB: JVNDB-2017-001380 // CNNVD: CNNVD-201701-787 // NVD: CVE-2017-3794

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.9

sources: VULHUB: VHN-111997 // JVNDB: JVNDB-2017-001380 // NVD: CVE-2017-3794

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201701-787

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201701-787

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-001380

PATCH

title:cisco-sa-20170118-wmsurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170118-wms

Trust: 0.8

title:Cisco WebEx Meetings Server Fixes for cross-site request forgery vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=67345

Trust: 0.6

sources: JVNDB: JVNDB-2017-001380 // CNNVD: CNNVD-201701-787

EXTERNAL IDS

db:NVDid:CVE-2017-3794

Trust: 2.9

db:BIDid:95635

Trust: 2.1

db:SECTRACKid:1037649

Trust: 1.2

db:JVNDBid:JVNDB-2017-001380

Trust: 0.8

db:CNNVDid:CNNVD-201701-787

Trust: 0.7

db:VULHUBid:VHN-111997

Trust: 0.1

db:VULMONid:CVE-2017-3794

Trust: 0.1

sources: VULHUB: VHN-111997 // VULMON: CVE-2017-3794 // BID: 95635 // JVNDB: JVNDB-2017-001380 // CNNVD: CNNVD-201701-787 // NVD: CVE-2017-3794

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20170118-wms

Trust: 2.1

url:http://www.securityfocus.com/bid/95635

Trust: 1.9

url:http://www.securitytracker.com/id/1037649

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-3794

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2017-3794

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/352.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-111997 // VULMON: CVE-2017-3794 // BID: 95635 // JVNDB: JVNDB-2017-001380 // CNNVD: CNNVD-201701-787 // NVD: CVE-2017-3794

CREDITS

Cisco

Trust: 0.9

sources: BID: 95635 // CNNVD: CNNVD-201701-787

SOURCES

db:VULHUBid:VHN-111997
db:VULMONid:CVE-2017-3794
db:BIDid:95635
db:JVNDBid:JVNDB-2017-001380
db:CNNVDid:CNNVD-201701-787
db:NVDid:CVE-2017-3794

LAST UPDATE DATE

2024-11-23T22:52:34.155000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-111997date:2017-07-26T00:00:00
db:VULMONid:CVE-2017-3794date:2017-07-26T00:00:00
db:BIDid:95635date:2017-01-23T01:11:00
db:JVNDBid:JVNDB-2017-001380date:2017-02-09T00:00:00
db:CNNVDid:CNNVD-201701-787date:2017-01-22T00:00:00
db:NVDid:CVE-2017-3794date:2024-11-21T03:26:07.733

SOURCES RELEASE DATE

db:VULHUBid:VHN-111997date:2017-01-26T00:00:00
db:VULMONid:CVE-2017-3794date:2017-01-26T00:00:00
db:BIDid:95635date:2017-01-18T00:00:00
db:JVNDBid:JVNDB-2017-001380date:2017-02-09T00:00:00
db:CNNVDid:CNNVD-201701-787date:2017-01-20T00:00:00
db:NVDid:CVE-2017-3794date:2017-01-26T07:59:00.310