ID

VAR-202008-0798


CVE

CVE-2020-3412


TITLE

Cisco Webex Meetings Unauthorized authentication vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-009447

DESCRIPTION

A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to create a scheduled meeting template that would belong to another user in their organization. The vulnerability is due to insufficient authorization enforcement for the creation of scheduled meeting templates. An attacker could exploit this vulnerability by sending a crafted request to the Webex Meetings interface to create a scheduled meeting template. A successful exploit could allow the attacker to create a scheduled meeting template that would belong to a user other than themselves. Cisco Webex Meetings Exists in a fraudulent authentication vulnerability.Information may be tampered with. Cisco Webex Meetings is a set of video conferencing solutions of Cisco (Cisco)

Trust: 1.71

sources: NVD: CVE-2020-3412 // JVNDB: JVNDB-2020-009447 // VULHUB: VHN-181537

AFFECTED PRODUCTS

vendor:ciscomodel:webex meetings onlinescope:ltversion:40.7.0

Trust: 1.0

vendor:ciscomodel:webex meetings onlinescope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-009447 // NVD: CVE-2020-3412

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-3412
value: MEDIUM

Trust: 1.0

ykramarz@cisco.com: CVE-2020-3412
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-009447
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202008-162
value: MEDIUM

Trust: 0.6

VULHUB: VHN-181537
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-3412
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-009447
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-181537
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-3412
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.1

Trust: 2.0

NVD: JVNDB-2020-009447
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-181537 // JVNDB: JVNDB-2020-009447 // CNNVD: CNNVD-202008-162 // NVD: CVE-2020-3412 // NVD: CVE-2020-3412

PROBLEMTYPE DATA

problemtype:CWE-863

Trust: 1.9

problemtype:CWE-284

Trust: 1.0

sources: VULHUB: VHN-181537 // JVNDB: JVNDB-2020-009447 // NVD: CVE-2020-3412

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202008-162

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-202008-162

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-009447

PATCH

title:cisco-sa-webex-smtcreate-YmuD5Skurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-smtcreate-YmuD5Sk

Trust: 0.8

title:Cisco Webex Meetings Fixes for access control error vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=125501

Trust: 0.6

sources: JVNDB: JVNDB-2020-009447 // CNNVD: CNNVD-202008-162

EXTERNAL IDS

db:NVDid:CVE-2020-3412

Trust: 2.5

db:JVNDBid:JVNDB-2020-009447

Trust: 0.8

db:CNNVDid:CNNVD-202008-162

Trust: 0.7

db:AUSCERTid:ESB-2020.2682

Trust: 0.6

db:VULHUBid:VHN-181537

Trust: 0.1

sources: VULHUB: VHN-181537 // JVNDB: JVNDB-2020-009447 // CNNVD: CNNVD-202008-162 // NVD: CVE-2020-3412

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-webex-smtcreate-ymud5sk

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-3412

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-3412

Trust: 0.8

url:https://www.auscert.org.au/bulletins/esb-2020.2682/

Trust: 0.6

sources: VULHUB: VHN-181537 // JVNDB: JVNDB-2020-009447 // CNNVD: CNNVD-202008-162 // NVD: CVE-2020-3412

SOURCES

db:VULHUBid:VHN-181537
db:JVNDBid:JVNDB-2020-009447
db:CNNVDid:CNNVD-202008-162
db:NVDid:CVE-2020-3412

LAST UPDATE DATE

2024-11-23T21:59:07.133000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-181537date:2020-08-19T00:00:00
db:JVNDBid:JVNDB-2020-009447date:2020-11-06T02:02:11
db:CNNVDid:CNNVD-202008-162date:2020-08-20T00:00:00
db:NVDid:CVE-2020-3412date:2024-11-21T05:30:58.883

SOURCES RELEASE DATE

db:VULHUBid:VHN-181537date:2020-08-17T00:00:00
db:JVNDBid:JVNDB-2020-009447date:2020-11-06T02:02:11
db:CNNVDid:CNNVD-202008-162date:2020-08-05T00:00:00
db:NVDid:CVE-2020-3412date:2020-08-17T18:15:12.760