CVE-2020-3361 is a critical vulnerability affecting Cisco Webex Meetings and Webex Meetings Server, stemming from improper handling of authentication tokens. An unauthenticated, remote attacker can exploit this by sending crafted requests, potentially gaining full control over another user's account within the Webex site. With a CVSS score of 9.8, this vulnerability is highly severe, allowing for complete compromise of confidentiality, integrity, and availability without user interaction. While not currently listed on the KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 39.5.25CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings:*:*:*:*:*:*:*:* | ||
>= 40.1.0, <= 40.4.10CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings:*:*:*:*:*:*:*:* | ||
40.6.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings:40.6.0:*:*:*:*:*:*:* | ||
< 4.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:cisco:webex_meetings_server:4.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.