Cisco Webex Meetings Services HTTP Cache Poisoning Vulnerability
TL;DR 📌
- A vulnerability in client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses within the meeting join service. This vulnerability is due to improper handling of malicious HTTP requests to the affected service. An attacker could exploit this vulnerability by manipulating stored HTTP responses within the service,…
- Highest CVSS: 4.3 (Medium).
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2025-20255.
What it is
CVE-2025-20255 affects the client join services in Cisco Webex Meetings, specifically the meeting join service that handles HTTP requests from clients connecting to a meeting. The flaw is due to improper handling of malicious HTTP requests, which allows an attacker to manipulate cached HTTP responses within the service — a classic HTTP cache poisoning issue.
An unauthenticated, remote attacker can exploit this over the network by sending crafted requests to the join service. No login or prior access to a meeting is required. Because this sits on the data plane that clients hit when joining a meeting, successful exploitation causes the Webex Meetings service to return incorrect HTTP responses to clients that subsequently request the poisoned cache entry.
The vulnerability affects Cisco Webex Meetings, which is cloud-based. Cisco rates this CVSS 4.3 (medium), reflecting the limited impact (integrity: low, no confidentiality or availability impact) and the requirement for user interaction.
Cisco PSIRT states it is not aware of any public announcements or malicious use of this vulnerability.
What to do
- No action is required from customers. Cisco has fixed this in the Webex Meetings cloud service directly, and there is nothing to patch on-premises.
- There are no workarounds, but none are needed given the service-side fix.
- If you run any on-premises Webex components alongside the cloud meeting service, confirm with Cisco TAC or your maintenance provider whether those components are in scope — the advisory limits the vulnerable product to the cloud-based Webex Meetings service itself.
- No further tracking is needed for this one beyond noting it’s closed; there’s no fixed-version action item to schedule.
For leadership 🧭
Executive summary. Cisco has already fixed this flaw in the cloud-hosted Webex Meetings join service, so there is no patch or configuration change for customers to make. It was rated medium severity with limited impact and no evidence of exploitation, so no urgent action is needed.
Why it matters:
- The flaw sits in the meeting join service that all Webex Meetings clients hit when connecting, meaning any client requesting a poisoned cache entry could receive an incorrect HTTP response.
- Exploitation required no authentication and no prior access to a meeting, only crafted HTTP requests to the join service from a remote attacker.
- Because Webex Meetings is cloud-based, the fix was applied directly by Cisco with no on-premises software or device update for customers to schedule.
- Impact is limited to integrity (rated low) with no confidentiality or availability effect, and requires user interaction, which keeps the practical risk modest.
Now / Next / Later:
- Now: Confirm this advisory in your tracking as closed with no customer action required, since Cisco has already remediated it server-side in the cloud service.
- Next: If your organisation runs any on-premises Webex components alongside the cloud meeting service, check with Cisco TAC or your maintenance provider to confirm those components fall outside the scope of this advisory.
- Later: Keep a routine process for reviewing Cisco Webex security advisories, since cloud-service fixes like this one are applied by Cisco directly and won’t appear as a version bump in your own patch management records.