ID

VAR-202008-0799


CVE

CVE-2020-3413


TITLE

Cisco Webex Meetings Unauthorized authentication vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-009448

DESCRIPTION

A vulnerability in the scheduled meeting template feature of Cisco Webex Meetings could allow an authenticated, remote attacker to delete a scheduled meeting template that belongs to another user in their organization. The vulnerability is due to insufficient authorization enforcement for requests to delete scheduled meeting templates. An attacker could exploit this vulnerability by sending a crafted request to the Webex Meetings interface to delete a scheduled meeting template. A successful exploit could allow the attacker to delete a scheduled meeting template that belongs to a user other than themselves. Cisco Webex Meetings Exists in a fraudulent authentication vulnerability.Information may be tampered with. Cisco Webex Meetings is a set of video conferencing solutions of Cisco (Cisco)

Trust: 1.71

sources: NVD: CVE-2020-3413 // JVNDB: JVNDB-2020-009448 // VULHUB: VHN-181538

AFFECTED PRODUCTS

vendor:ciscomodel:webex meetings onlinescope:ltversion:40.7.0

Trust: 1.0

vendor:ciscomodel:webex meetings onlinescope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-009448 // NVD: CVE-2020-3413

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-3413
value: MEDIUM

Trust: 1.0

ykramarz@cisco.com: CVE-2020-3413
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-009448
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202008-163
value: MEDIUM

Trust: 0.6

VULHUB: VHN-181538
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-3413
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-009448
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-181538
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-3413
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 1.4
version: 3.1

Trust: 2.0

NVD: JVNDB-2020-009448
baseSeverity: MEDIUM
baseScore: 4.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-181538 // JVNDB: JVNDB-2020-009448 // CNNVD: CNNVD-202008-163 // NVD: CVE-2020-3413 // NVD: CVE-2020-3413

PROBLEMTYPE DATA

problemtype:CWE-863

Trust: 1.9

problemtype:CWE-284

Trust: 1.0

sources: VULHUB: VHN-181538 // JVNDB: JVNDB-2020-009448 // NVD: CVE-2020-3413

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202008-163

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-202008-163

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-009448

PATCH

title:cisco-sa-webex-smtdelete-gJDurOgRurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-smtdelete-gJDurOgR

Trust: 0.8

title:Cisco Webex Meetings Fixes for access control error vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=125502

Trust: 0.6

sources: JVNDB: JVNDB-2020-009448 // CNNVD: CNNVD-202008-163

EXTERNAL IDS

db:NVDid:CVE-2020-3413

Trust: 2.5

db:JVNDBid:JVNDB-2020-009448

Trust: 0.8

db:CNNVDid:CNNVD-202008-163

Trust: 0.7

db:AUSCERTid:ESB-2020.2682

Trust: 0.6

db:CNVDid:CNVD-2020-45576

Trust: 0.1

db:VULHUBid:VHN-181538

Trust: 0.1

sources: VULHUB: VHN-181538 // JVNDB: JVNDB-2020-009448 // CNNVD: CNNVD-202008-163 // NVD: CVE-2020-3413

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-webex-smtdelete-gjdurogr

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-3413

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-3413

Trust: 0.8

url:https://www.auscert.org.au/bulletins/esb-2020.2682/

Trust: 0.6

sources: VULHUB: VHN-181538 // JVNDB: JVNDB-2020-009448 // CNNVD: CNNVD-202008-163 // NVD: CVE-2020-3413

SOURCES

db:VULHUBid:VHN-181538
db:JVNDBid:JVNDB-2020-009448
db:CNNVDid:CNNVD-202008-163
db:NVDid:CVE-2020-3413

LAST UPDATE DATE

2024-11-23T21:59:07.211000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-181538date:2020-08-19T00:00:00
db:JVNDBid:JVNDB-2020-009448date:2020-11-06T02:02:12
db:CNNVDid:CNNVD-202008-163date:2020-08-20T00:00:00
db:NVDid:CVE-2020-3413date:2024-11-21T05:30:59

SOURCES RELEASE DATE

db:VULHUBid:VHN-181538date:2020-08-17T00:00:00
db:JVNDBid:JVNDB-2020-009448date:2020-11-06T02:02:12
db:CNNVDid:CNNVD-202008-163date:2020-08-05T00:00:00
db:NVDid:CVE-2020-3413date:2020-08-17T18:15:12.867