Update Cisco Webex Meetings immediately

Cisco today fixed three security vulnerabilities in Webex Meetings that allowed unauthorized remote intruders to participate in meetings as ghost participants.

Cisco Webex is an online conference and video conferencing software that can be used to schedule and schedule meetings. Provides users with presentation, screen sharing and recording capabilities.

Cisco's remote meeting platform has seen a 451% increase in usage over four months due to the COVID-19 pandemic, and is hosting approximately 4 meetings per day for 324 million users at its peak.

Malicious users who abused the patched security holes could become "ghost" users and could join a meeting without being detected, IBM researchers discovered while analyzing the tool plus of Cisco for vulnerabilities.

"Ghost" users are participants in a meeting that are not visible in the list of users and have not been invited to the meeting, but can listen, talk and share in the meeting.

The three errors also allowed attackers to remain in the Webex meeting and maintain a two-way audio connection even after being removed by administrators who had access to Webex users' information, such as email addresses and IP addresses from the meeting room. .

IBM researchers made the following errors that allowed the attackers to:

  • Participate in a Webex meeting as "Ghost" without appearing on the attendee list with full access to audio, video, chat and screen sharing features (CVE-2020-3419)
  • Stay in a Webex meeting as a "Ghost" even if they are expelled from it, maintaining the audio connection (CVE-2020-3471)
  • Access information about meeting participants – full names, email addresses y and IP addresses even without being admitted to the call (CVE-2020-3441)

Cisco recommends that users update to the latest immediately of Webex to secure meetings from attackers who would try to exploit the above vulnerabilities.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).