CVE-2021-1410 (CNNVD-202103-319)
中文标题:
Cisco Webex Meetings 访问控制错误漏洞
英文标题:
Cisco Webex Meetings Unauthorized Distribution List Update Vulnerability
漏洞描述
中文描述:
Cisco Webex Meetings是美国思科(Cisco)公司的一个视频会议和在线会议软件。提供带有共享、聊天等功能的视频和音频会议。 Cisco Webex Meetings 存在访问控制错误漏洞,该漏洞源于对更新分发列表的请求授权执行不足。攻击者可利用该漏洞修改属于用户而不是自己的分布列表。
英文描述:
A vulnerability in the distribution list feature of Cisco Webex Meetings could allow an authenticated, remote attacker to modify a distribution list that belongs to another user of their organization. The vulnerability is due to insufficient authorization enforcement for requests to update distribution lists. An attacker could exploit this vulnerability by sending a crafted request to the Webex Meetings interface to modify an existing distribution list. A successful exploit could allow the attacker to modify a distribution list that belongs to a user other than themselves.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Cisco | Cisco Webex Meetings | 39.7.7 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.7.7:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.9 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.9:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 40.4.10 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:40.4.10:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.6 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.6:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 40.6.2 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:40.6.2:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.8.2 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.8.2:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.8.4 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.8.4:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 40.1 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:40.1:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.11 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.11:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.7.4 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.7.4:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.9.1 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.9.1:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 40.4 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:40.4:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 40.6 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:40.6:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.7 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.7:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.8 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.8:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.8.3 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.8.3:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 40.2 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:40.2:*:*:*:*:*:*:*
|
| Cisco | Cisco Webex Meetings | 39.10 | - | - |
cpe:2.3:a:cisco:cisco_webex_meetings:39.10:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.6 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.6:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.7 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.7:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.7.4 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.7.4:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.7.7 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.7.7:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.8 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.8:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.8.2 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.8.2:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.8.3 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.8.3:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.8.4 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.8.4:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.9 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.9:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.9.1 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.9.1:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.10 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.10:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 39.11 | - | - |
cpe:2.3:a:cisco:webex_meetings:39.11:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 40.1 | - | - |
cpe:2.3:a:cisco:webex_meetings:40.1:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 40.2 | - | - |
cpe:2.3:a:cisco:webex_meetings:40.2:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 40.4 | - | - |
cpe:2.3:a:cisco:webex_meetings:40.4:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 40.4.10 | - | - |
cpe:2.3:a:cisco:webex_meetings:40.4.10:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 40.6 | - | - |
cpe:2.3:a:cisco:webex_meetings:40.6:*:*:*:*:*:*:*
|
| cisco | webex_meetings | 40.6.2 | - | - |
cpe:2.3:a:cisco:webex_meetings:40.6.2:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/RL:X/RC:X/E:X
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2021-1410 |
2025-11-11 15:20:45 | 2025-11-11 07:36:33 |
| NVD | nvd_CVE-2021-1410 |
2025-11-11 14:57:53 | 2025-11-11 07:44:55 |
| CNNVD | cnnvd_CNNVD-202103-319 |
2025-11-11 15:10:35 | 2025-11-11 07:56:40 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-202103-319
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 18 -> 36
- data_sources: ['cve'] -> ['cve', 'nvd']