CVE-2021-1311
MEDIUMCisco Webex Meetings < 40.12.0 and Webex Meetings Server < 3.0 - Authenticated Host Role Takeover via Brute Force
Title source: llmDescription
A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host key. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Webex Meetings Server site. A successful exploit would require the attacker to have access to join a Webex meeting, including applicable meeting join links and passwords. A successful exploit could allow the attacker to acquire or take over the host role for a meeting.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-brutef-hostkey-FWRMxVF
Scores
CVSS v3
5.4
EPSS
0.0036
EPSS Percentile
58.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-307
Status
published
Products (4)
cisco/webex_meetings
< 40.12.0
cisco/webex_meetings_server
3.0 (5 CPE variants)
cisco/webex_meetings_server
4.0 (4 CPE variants)
cisco/webex_meetings_server
< 3.0
Published
Jan 13, 2021
Tracked Since
Feb 18, 2026