CVE-2017-12224 describes a vulnerability in Cisco Meeting Server where guest users could bypass intended access restrictions and join meetings via a hyperlink, even when guest access via hyperlinks was configured to be denied. The vulnerability stems from an incorrect implementation of this configuration setting. With a CVSS score of 6.5 (Medium), this flaw allows an authenticated, remote attacker to gain unauthorized access to meetings, potentially leading to information disclosure (C:H). While the attacker still requires a valid hyperlink and encoded secret identifier, the vulnerability circumvents the administrative control designed to prevent such access. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:meeting_server:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.