PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-3797 Cisco CVE debrief

CVE-2017-3797 is an information disclosure issue in Cisco WebEx Meetings Server. An unauthenticated remote attacker could view the fully qualified domain name of the Cisco WebEx administration server. NVD rates the issue CVSS 3.0 5.3/Medium, with confidentiality impact limited and no integrity or availability impact recorded.

Vendor
Cisco
Product
Webex Meetings Server
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-26
Original CVE updated
2026-05-13
Advisory published
2017-01-26
Advisory updated
2026-05-13

Who should care

Administrators and security teams responsible for Cisco WebEx Meetings Server deployments, especially systems running affected 2.7-era releases or exposed administration services.

Technical summary

The vulnerability is categorized as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). NVD lists the attack vector as network-based, with no privileges required and no user interaction (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). The documented impact is limited to disclosure of the administration server's fully qualified domain name. NVD identifies affected CPEs for Cisco WebEx Meetings Server 2.7_base and 2.7.1, and the CVE description calls out known affected releases 2.7.

Defensive priority

Medium priority. This is a remote, unauthenticated information disclosure issue, so it should be addressed through the vendor's guidance during the next normal maintenance cycle, with extra attention if the service is reachable from untrusted networks.

Recommended defensive actions

  • Review Cisco's advisory for CVE-2017-3797 and apply the vendor-recommended remediation for WebEx Meetings Server.
  • Inventory Cisco WebEx Meetings Server deployments and confirm whether affected 2.7-era releases are present, including 2.7_base and 2.7.1.
  • Restrict access to administration interfaces to trusted management networks and minimize external exposure.
  • Validate that server naming and administrative metadata are not exposed beyond intended administrative users.
  • Update internal vulnerability tracking and retest the affected systems after remediation.

Evidence notes

Source corpus and official references consistently describe a Cisco WebEx Meetings Server information disclosure issue affecting known release 2.7. NVD lists the weakness as CWE-200 and the CVSS v3 vector as AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. NVD also enumerates vulnerable CPEs for cisco:webex_meetings_server:2.7.1 and cisco:webex_meetings_server:2.7_base. Cisco's security advisory is referenced in the NVD record, along with third-party advisory listings.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-3797 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-3797

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-3797 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3797

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.