ZeroHour
Cisco Security Advisoriespublished ()ingested

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

lowAdvisoryimportance 26
AI summary · glm-5.3-flash

Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.

  • Missing authorization checks in CommPilot web management interface
  • Exploitation requires valid low-privileged credentials
  • Impact limited to altering configurations on select pages
  • No workarounds; software updates are the only fix
VendorsCisco
OrganizationsCisco
Full article

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to alter configurations on select pages. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.