Security News

Cisco Patches Remote Code Execution Flaws in Webex Player
2020-03-04 21:06

Cisco has released patches to address more than a dozen vulnerabilities across various products, including two code execution bugs in Webex Player that could be exploited remotely. Tracked as CVE-2020-3127 and CVE-2020-3128 and rated high severity, the issues reside in the insufficient validation of elements within a Webex recording stored as ARF or WRF. To exploit the bugs, an attacker needs to send a malicious ARF or WRF file and trick the victim into opening the file the local system, which could result in arbitrary code being executed with the privileges of the targeted user.

Cisco adds AI-powered voice intelligence capabilities to Webex Meetings
2020-01-29 01:30

Cisco is introducing new AI-powered voice intelligence capabilities to Webex Meetings to help turn talk into action. The Cisco Webex Assistant for Webex Meetings is powered by technology from the recent Voicea acquisition, turning Webex meetings into a digital treasure trove.

Cisco patches bugs in security admin center and Webex
2020-01-28 10:50

Cisco has patched a critical bug that could give attackers unauthorised access to Firepower Management Centre, the device that controls all of its security products. Cisco's FMC is an administrative controller for the company's network security products, giving administrators access to firewalls, application controllers, intrusion prevention, URL filtering, and malware protection systems.

Cisco Webex bug allowed anyone to join a password-protected meeting
2020-01-27 14:44

Cisco has confessed to a vulnerability in its Webex Meetings Suite sites and Webex Meetings Online sites that allowed an "Unauthenticated" attendee sitting on a workstation far, far away to join a "Password-protected meeting without providing the meeting password". According to the security advisory, which was rated as "High": "The vulnerability is due to unintended meeting information exposure in a specific meeting join flow for mobile applications."

Cisco Webex Vulnerability Exploited to Join Meetings Without a Password
2020-01-25 12:36

Cisco on Friday informed customers that it has patched a vulnerability that allowed unauthorized users to join password-protected Webex meetings. The vulnerability, tracked as CVE-2020-3142 and classified as high severity, affected Cisco Webex Meetings Suite sites and Cisco Webex Meetings Online sites, releases earlier than 39.11.5 and 40.1.3.

Cisco Webex Flaw Lets Unauthenticated Users Join Private Online Meetings
2020-01-24 19:27

UPDATE. Cisco Systems has fixed a high-severity vulnerability in its popular Webex video conferencing platform, which could let strangers barge in on password-protected meetings - no authentication necessary. "The vulnerability is due to unintended meeting information exposure in a specific meeting join flow for mobile applications," Cisco said.

Cisco Webex Bug Allows Remote Code Execution
2020-01-10 17:24

Cisco Systems has fixed two high-severity vulnerabilities in its products, including one in its popular Webex video conferencing platform that could enable a remote attacker to execute commands. The high-severity Webex flaw exists in the web-based management interface of Cisco Webex Video Mesh, a feature that enables on-premises infrastructure for video conferencing, to enhance audio, video and content.

Ding-dong: Cisco delivers your Patch Tuesday warm-up with WebEx, IOS fixes for a few irritating security holes
2020-01-10 00:58

Cisco has released a fresh batch of security updates for its networking and comms gear lines. The high-priority patch this month is the fix for CVE-2019-16009, a cross-site request forgery, in the web UI of Cisco IOS and Cisco IOS XE that can be exploited to steal credentials from users via malicious links.

WebEx, Zoom Meetings Exposed to Snooping via Enumeration Attacks
2019-10-01 14:05

Malicious actors may be able to easily access unprotected Cisco WebEx and Zoom meetings due to an API enumeration vulnerability, Cequence Security’s CQ Prime threat research team revealed on...

Vulnerability in Cisco Webex and Zoom may expose online meetings to snooping
2019-10-01 10:55

Cequence Security’s CQ Prime Threat Research Team discovered of a vulnerability in Cisco Webex and Zoom video conferencing platforms that potentially allows an attacker to enumerate or list and...