MEDIUM · 4.3

CVE-2014-3310

The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not verify that a requested file was an offered file, which allows remote attackers to r...

Vulnerability Description

The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not verify that a requested file was an offered file, which allows remote attackers to read arbitrary files via a modified request, aka Bug IDs CSCup62442 and CSCup58463.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoWebex Meeting Center-
CiscoWebex Meetings Server-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-3310?

CVE-2014-3310 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not verify that a requested file was an offered file, which allows remote attackers to r...

How severe is CVE-2014-3310?

CVE-2014-3310 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-3310?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Webex Meeting Center, Cisco Webex Meetings Server.