CVE-2021-1410
Cisco Webex Meetings vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2021-1410) was discovered in the distribution list feature of Cisco Webex Meetings that could allow an authenticated, remote attacker to modify a distribution list belonging to another user within their organization. The vulnerability was disclosed on March 3, 2021, affecting Cisco Webex Meetings releases earlier than 41.2.0 (Cisco Advisory).

Technical details

The vulnerability stems from insufficient authorization enforcement for requests to update distribution lists in Cisco Webex Meetings. It has been assigned a CVSS base score of 4.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N. The vulnerability is classified as CWE-284 (Improper Access Control) (Cisco Advisory).

Impact

A successful exploitation of this vulnerability would allow an attacker to modify distribution lists belonging to other users within their organization, potentially leading to unauthorized changes in communication groups (Cisco Advisory).

Exploitability

The vulnerability can be exploited by sending a crafted request to the Webex Meetings interface to modify an existing distribution list. At the time of disclosure, Cisco PSIRT was not aware of any public announcements or malicious exploitation of this vulnerability (Cisco Advisory).

Mitigation and workarounds

Cisco has released software updates that address this vulnerability in Webex Meetings Release 41.2.0 and later. No user action is required as the service is cloud-based. There are no workarounds available for this vulnerability. Customers can verify their current remediation status or software version through the Help function in the service GUI (Cisco Advisory).

Additional resources


SourceThis report was generated using AI

Related Cisco Webex Meetings vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20184CRITICAL9.8
  • Cisco Webex Meetings logoCisco Webex Meetings
  • cpe:2.3:a:cisco:webex_meetings
NoYesApr 15, 2026
CVE-2026-20233MEDIUM6.1
  • Cisco Webex Meetings logoCisco Webex Meetings
  • cpe:2.3:a:cisco:webex_meetings
NoYesJun 03, 2026
CVE-2022-20654MEDIUM6.1
  • Cisco Webex Meetings logoCisco Webex Meetings
  • cpe:2.3:a:cisco:webex_meetings
NoYesNov 15, 2024
CVE-2026-20219MEDIUM5.4
  • Cisco Webex Meetings logoCisco Webex Meetings
  • cpe:2.3:a:cisco:webex_meetings
NoYesMay 06, 2026
CVE-2021-1410MEDIUM4.3
  • Cisco Webex Meetings logoCisco Webex Meetings
  • cpe:2.3:a:cisco:webex_meetings
NoYesNov 18, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management