VulnerabilityModified
CVE-2015-0583
Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors related to file: URIs, aka Bug ID CSCus18281.
MEDIUM 5.0EPSS 1.35%
Does this matter?
Lower severity and a low EPSS score (1.35%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors related to file: URIs, aka Bug ID CSCus18281.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- cisco/webex meeting center
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0583Vendor Advisory
- http://www.securityfocus.com/bid/72012
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100565
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0583Vendor Advisory
- http://www.securityfocus.com/bid/72012
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100565
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.