Vulnerability Database

296,746

Total vulnerabilities in the database

CVE-2021-1311

A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to take over the host role during a meeting. This vulnerability is due to a lack of protection against brute forcing of the host key. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Webex Meetings Server site. A successful exploit would require the attacker to have access to join a Webex meeting, including applicable meeting join links and passwords. A successful exploit could allow the attacker to acquire or take over the host role for a meeting.

  • Published: Jan 13, 2021
  • Updated: Apr 14, 2023
  • CVE: CVE-2021-1311
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.4
  • AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CVSS v2:

  • Severity: Medium
  • Score: 5.5
  • AV:N/AC:L/Au:S/C:N/I:P/A:P

CWEs:

Software From Fixed in
cisco / webex_meetings_server - 3.0
cisco / webex_meetings_server 3.0-maintenance_release1 3.0-maintenance_release1.x
cisco / webex_meetings_server 3.0 3.0.x
cisco / webex_meetings_server 3.0-maintenance_release2 3.0-maintenance_release2.x
cisco / webex_meetings_server 3.0-maintenance_release3 3.0-maintenance_release3.x
cisco / webex_meetings_server 4.0 4.0.x
cisco / webex_meetings_server 4.0-maintenance_release1 4.0-maintenance_release1.x
cisco / webex_meetings_server 4.0-maintenance_release2 4.0-maintenance_release2.x
cisco / webex_meetings_server 4.0-maintenance_release3 4.0-maintenance_release3.x
cisco / webex_meetings_server 3.0-maintenance_release4 3.0-maintenance_release4.x
cisco / webex_meetings - 40.12.0