SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3340

Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCuo16166.

MEDIUM 4.0EPSS 2.25%

Does this matter?

Lower severity and a low EPSS score (2.25%). Track it; it rarely justifies an emergency change on its own.

Description

Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCuo16166.

CVSS 2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
2.25% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
cisco/webex meetmenow
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.