News
Cisco warns of low-severity Webex vulnerability affecting sensitive data
Cisco warns of a low-severity vulnerability in Webex for BroadWorks, potentially exposing sensitive data through insecure SIP communication. Users are advised to take action.

- March 5, 2025
- Updated: July 1, 2025 at 10:15 PM

Cisco has issued a warning regarding a low-severity vulnerability in the 45.2 version of its Webex for BroadWorks application, potentially allowing remote access to sensitive data. This cloud collaboration solution integrates video conferencing with networks based on BroadWorks, catering to businesses with functionalities like messaging, calling, and meeting capabilities.
The vulnerability arises from the exposure of sensitive information within Session Initiation Protocol (SIP) headers. If users have configured an insecure transport for SIP communication, malicious actors could access data and credentials that may be logged in plaintext on both client and server sides. Cisco cautions that this flaw enables unauthorized users to impersonate legitimate users, posing significant security risks.
No evidence of exploitation but Cisco urges credential rotation
In response to the discovery, Cisco has advised users to restart their Webex applications to implement the necessary configuration changes that rectify the issue. For those unable to restart, the company has suggested that administrators configure secure transport for SIP communications as an alternative solution to encrypt data in transit.
Additionally, Cisco recommends that all users rotate their credentials as a precautionary measure against potential exploitation, emphasizing the importance of safeguarding sensitive information. Fortunately, there has been no evidence so far that this vulnerability has been actively exploited in the wild.
This announcement follows Cisco’s early February 2025 patch release for two critical vulnerabilities affecting its Identity Services Engine, which had the potential for arbitrary command execution and sensitive data theft. The quick responses by Cisco reflect its commitment to maintaining robust security standards for its applications.
Latest from Agencias
- James Gunn clarifies the future of Harley Quinn after years of being a DC icon
- South Korea has grown in streaming much more than expected. They have to thank themselves
- One of the most controversial (and brave) artists in history will have her own biopic
- We have been waiting 15 years for the end of one of the best mangas in history. And now, finally, it is going to arrive
You may also like
- News
The infinite canvas: use of Generative Expand for print bleeds and concept exploration
Read more
- News
James Gunn clarifies the future of Harley Quinn after years of being a DC icon
Read more
- News
South Korea has grown in streaming much more than expected. They have to thank themselves
Read more
- News
One of the most controversial (and brave) artists in history will have her own biopic
Read more
- News
We have been waiting 15 years for the end of one of the best mangas in history. And now, finally, it is going to arrive
Read more
- News
Thunderbolts is coming to Disney+ sooner than you thought: This will be the release date on the platform
Read more