CVE-2017-3823 is a critical design defect in Cisco WebEx browser extensions for Chrome, Firefox, and Internet Explorer, affecting WebEx Meetings Server and various WebEx Centers on Windows. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary code with browser privileges by tricking a user into visiting a malicious webpage. With a CVSS score of 8.8 (High) and an EPSS percentile of 0.80391, it represents a significant risk due to its network-based attack vector and low attack complexity, leading to high impact on confidentiality, integrity, and availability. While not listed in CISA KEV, a Metasploit module exists, and it has garnered substantial community discussion and media coverage, indicating its exploitability and widespread awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
105CPE matchmatch criteria | cpe:2.3:a:cisco:activetouch_general_plugin_container:105:*:*:*:*:firefox:*:* | ||
2.1.0.9CPE matchmatch criteria | cpe:2.3:a:cisco:download_manager:2.1.0.9:*:*:*:*:internet_explorer:*:* | ||
<= 10031.6.2017.0125CPE matchmatch criteria | cpe:2.3:a:cisco:gpccontainer_class:*:*:*:*:*:internet_explorer:*:* | ||
<= 1.0.6CPE matchmatch criteria | cpe:2.3:a:cisco:webex:*:*:*:*:*:chrome:*:* | ||
2.0_baseCPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:2.0_base:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.