CVE-2017-12297
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to arbitrary hosts, aka a "URL Redirection Vulnerability." The vulnerability is due to insufficient access control for HTTP traffic directed to the Cisco WebEx Meeting Center. An attacker could exploit this vulnerability by sending a malicious URL to the Cisco WebEx Meeting Center. An exploit could allow the attacker to connect to arbitrary hosts. Cisco Bug IDs: CSCvf63843.
Una vulnerabilidad en Cisco WebEx Meeting Center podría permitir a un atacante remoto autenticado iniciar conexiones con hosts arbitrarios. Esta vulnerabilidad también se conoce como "URL Redirection Vulnerability". La vulnerabilidad se debe a un control insuficiente de acceso para el tráfico HTTP dirigido a Cisco WebEx Meeting Center. Un atacante podría explotar esta vulnerabilidad enviando una URL maliciosa a Cisco WebEx Meeting Center. Esta vulnerabilidad podría permitir que el atacante se conecte a hosts arbitrarios. Cisco Bug IDs: CSCvf63843.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-03 CVE Reserved
- 2017-11-30 CVE Published
- 2023-04-23 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101985 | Third Party Advisory | |
http://www.securitytracker.com/id/1039919 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-wmc | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t30 Search vendor "Cisco" for product "Webex Meeting Center" and version "t30" | sp7 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t30 Search vendor "Cisco" for product "Webex Meeting Center" and version "t30" | sp8 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t30 Search vendor "Cisco" for product "Webex Meeting Center" and version "t30" | sp9 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t31 Search vendor "Cisco" for product "Webex Meeting Center" and version "t31" | sp8 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t31 Search vendor "Cisco" for product "Webex Meeting Center" and version "t31" | sp9 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t32 Search vendor "Cisco" for product "Webex Meeting Center" and version "t32" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t32.3 Search vendor "Cisco" for product "Webex Meeting Center" and version "t32.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t32.4 Search vendor "Cisco" for product "Webex Meeting Center" and version "t32.4" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t32.6 Search vendor "Cisco" for product "Webex Meeting Center" and version "t32.6" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t32.7 Search vendor "Cisco" for product "Webex Meeting Center" and version "t32.7" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Webex Meeting Center Search vendor "Cisco" for product "Webex Meeting Center" | t32.8 Search vendor "Cisco" for product "Webex Meeting Center" and version "t32.8" | - |
Affected
|