VulnerabilityModified
CVE-2017-3811
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system.
MEDIUM 6.5EPSS 1.43%
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc39165. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.2054.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.43% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- cisco/webex meetings server
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/96912Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038042
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-wmsVendor Advisory
- http://www.securityfocus.com/bid/96912Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038042
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170315-wmsVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.