CVE-2021-34743
Cisco Webex Software Application Authorization Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to improper validation of cross-site request forgery (CSRF) tokens. An attacker could exploit this vulnerability by convincing a targeted user who is currently authenticated to Cisco Webex Software to follow a link designed to pass malicious input to the Cisco Webex Software application authorization interface. A successful exploit could allow the attacker to cause Cisco Webex Software to authorize an application on the user's behalf without the express consent of the user, possibly allowing external applications to read data from that user's profile.
Una vulnerabilidad en la funcionalidad application integration de Cisco Webex Software podría permitir a un atacante remoto no autenticado autorizar a una aplicación externa a integrarse y acceder a la cuenta de un usuario sin el consentimiento expreso de éste. Esta vulnerabilidad es debido a una comprobación inapropiada los tokens de tipo cross-site request forgery (CSRF). Un atacante podría explotar esta vulnerabilidad al convencer a un usuario objetivo que esté autenticado en el software Cisco Webex para que siga un enlace diseñado para pasar una entrada maliciosa a la interfaz de autorización de la aplicación del software Cisco Webex. Una explotación con éxito podría permitir al atacante causar que Cisco Webex Software autorice una aplicación en nombre del usuario sin el consentimiento expreso de éste, permitiendo posiblemente que aplicaciones externas lean datos del perfil de ese usuario
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2021-06-15 CVE Reserved
- 2021-10-21 CVE Published
- 2024-10-24 EPSS Updated
- 2024-11-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-2FmKd7T | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Webex Meetings Search vendor "Cisco" for product "Webex Meetings" | - | - |
Affected
|