VulnerabilityModified
CVE-2014-8034
Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.
MEDIUM 5.0EPSS 1.37%
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- cisco/webex meetings server
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8034Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=36990Vendor Advisory
- http://www.securityfocus.com/bid/71978
- http://www.securitytracker.com/id/1031543
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100552
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-8034Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=36990Vendor Advisory
- http://www.securityfocus.com/bid/71978
- http://www.securitytracker.com/id/1031543
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100552
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.