Cisco Webex Meetings Services HTTP Cache Poisoning Vulnerability
TL;DR 📌
A medium-severity HTTP cache poisoning vulnerability has been identified in Cisco Webex Meetings Services. No user action is required as Cisco has addressed the issue in the cloud-based service.
What happened 🕵️♂️
A vulnerability in the client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses. This issue arises from improper handling of malicious HTTP requests, potentially leading to incorrect HTTP responses being returned to clients. Fortunately, Cisco has already resolved this vulnerability, and no customer action is necessary to update on-premises software or devices.
Affected products 🖥️
This vulnerability specifically affects Cisco Webex Meetings, which is a cloud-based service.
Fixed software 🔧
Upgrade to at least the first fixed release in your train (or later):
| Product / Release Train | First Fixed Release | Notes |
|---|---|---|
| ISE / ISE-PIC 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available to address this vulnerability.
Risk in context 🎯
The vulnerability has a CVSS score of 4.3, indicating a medium severity level. While it poses a risk of HTTP cache poisoning, the fact that Cisco has already patched the issue and no user action is required mitigates the immediate threat.
Fast facts ⚡
- Advisory ID: cisco-sa-webex-cache-Q4xbkQBG
- CVSS Score: 4.3 (Medium)
- Vulnerability Type: HTTP Cache Poisoning
- Affected Product: Cisco Webex Meetings (cloud-based)
- Exploitation: No known public exploitation or announcements.
For leadership 🧭
Executive summary. An unauthenticated remote attacker could have caused Webex Meetings’ join service to cache and serve incorrect HTTP responses to clients, but Cisco has already remediated this on the cloud-hosted service. There is no action required and no urgency, since no on-premises component or customer-managed software is affected.
Why it matters:
- The flaw sat in the client join services of Webex Meetings, the component users hit before entering a meeting, so any poisoning would have affected what clients received at that stage.
- Cisco runs Webex Meetings as a cloud service, so the fix has already been applied centrally without customers needing to patch anything.
- No workaround exists, which would have mattered had the fix not already been deployed, but is now moot given Cisco’s server-side remediation.
- There is no indication of exploitation, and the medium CVSS score of 4.3 reflects a bounded, already-closed exposure window.
Now / Next / Later:
- Now: Confirm with your Cisco account team or admin console that your Webex Meetings tenant is running current cloud infrastructure; no patching action is needed on your side.
- Next: Update internal records to note this advisory as resolved by Cisco with no customer-side remediation required, so it doesn’t linger on patch-tracking lists.
- Later: Keep monitoring Cisco Webex security advisories for future client-side or join-service issues, since this component sits directly in the meeting-access path for your users.