CVE-2023-20255: Cisco Meeting Server

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP packets to an affected device. A successful exploit could allow the attacker to cause a partial availability condition, which could cause ongoing video calls to be dropped due to the invalid packets reaching the Web Bridge.

Affected products

  • Cisco Meeting Server: before 3.6.1 (fixed in 3.6.1)

Published 2023-11-01. Last modified 2026-06-17.