CVE-2020-3126

LOW

Cisco Webex Meetings Server - Authenticated Security Bypass via Multimedia Viewer Missing Warning Dialog

Title source: llm
STIX 2.1

Description

vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes when a room host views shared multimedia files. An authenticated, remote attacker could exploit this vulnerability by using the host role to share files within the Multimedia sharing feature and convincing a former room host to view that file. A warning dialog normally appears cautioning users before the file is displayed; however, the former host would not see that warning dialog, and any shared multimedia would be rendered within the user's browser. The attacker could leverage this behavior to conduct additional attacks by including malicious files within a targeted room host's browser window.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_cisco
https://quickview.cloudapps.cisco.com/quickview/bug/CSCvs24436

Scores

CVSS v3 3.0
EPSS 0.0012
EPSS Percentile 31.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-20
Status published
Products (1)
cisco/webex_meetings_server t39.3
Published Apr 13, 2020
Tracked Since Feb 18, 2026