Cisco warns some Webex users of worrying security flaw, so patch now


- Cisco warn of new vulnerability in Webex for BroadWorks
- The flaw allowed threat actors to steal sensitive files remotely
- A fix was already deployed, and users should update immediately
Cisco has warned Webex for BroadWorks users of a vulnerability that could allow threat actors to access sensitive data remotely.
Cisco Webex for BroadWorks is a cloud collaboration solution that integrates the video conferencing tool with BroadWorks-based service provider networks, offering messaging, calling, and meeting capabilities for businesses.
In a security advisory published on Cisco’s website, the company said that it uncovered a low-severity vulnerability in the app’s Release 45.2, which allowed malicious actors access to sensitive data if unsecure transport is configured for the SIP communication.
You may like
Exploiting the flaw
“This vulnerability is due to the exposure of sensitive information in the SIP headers,” Cisco explained.
It also added that it discovered a related issue that could allow an unauthenticated user to access credentials in plain text, in the client and server logs.
“A malicious actor could exploit this vulnerability and the related issue to access data and credentials and impersonate the user,” Cisco warned.
Since the company already made a configuration change that will fix both the vulnerability and the related issue, users are recommended to restart their Cisco Webex applications to apply the changes. For those who would rather deploy a workaround, Cisco said admins could configure secure transport for SIP communication to encrypt data in transit.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“Cisco also recommends rotating credentials to protect against the possibility that the credentials have been acquired by a malicious actor,” the advisory concludes. So far, there has been no evidence that the vulnerability was abused in the wild.
In early February 2025, Cisco released patches for two critical-severity vulnerabilities plaguing its Identity Services Engine (ISE) solution. Both could have been used to run arbitrary commands and steal sensitive information.
Since the fix was already deployed, it advised its customers to restart the application to apply the configuration changes.
Via BleepingComputer
You might also like
Cisco warn of new vulnerability in Webex for BroadWorks The flaw allowed threat actors to steal sensitive files remotely A fix was already deployed, and users should update immediately Cisco has warned Webex for BroadWorks users of a vulnerability that could allow threat actors to access sensitive data remotely. Cisco…
Recent Posts
- Android 16’s answer to iOS Live Activities is coming soon – here are the apps it’ll support, including Google Maps
- Laid-off workers should use AI to manage their emotions, says Xbox exec
- Hundreds of Android apps band together in massive scam campaign targeting millions – here’s what we know
- GM’s Cruise Cars Are Back on the Road in Three US States—But Not for Ride-Hailing
- The Ploopy Knob is an open-source control dial for your PC
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021