Cisco Webex Meetings Enumeration Attack

Cisco Webex Meetings is an enterprise solution for hosting online meetings that offers video conferencing, screen sharing, and webinar capabilities that support hundreds of participants. Cisco Webex Meetings utilizes a nine-digit number as a user-friendly meeting identifier that can be easily typed in to join a meeting from all types of endpoints.

On July 24th, 2019, Shreyans Mehta of Cequence Security and the CQ Prime Research Team reported to Cisco that an attacker could take advantage of one of the Webex Meetings API calls to enumerate all the meeting numbers in use by an organization on the platform at a certain moment in time.

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191001-webex-enum

Security Impact Rating: Informational

Related:

  • No Related Posts

Leave a Reply