30
30
60
60
Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability
Cisco patched an XXE flaw in BroadWorks' OCI XML parser letting unauthenticated remote attackers read sensitive files from the filesystem.
Cisco BroadWorks permits external entity resolution by default in its Open Client Interface XML parser, enabling out-of-band blind XXE injection. An unauthenticated remote attacker can send crafted XML to the OCI-P provisioning service and read sensitive configuration files with BroadWorks user privileges. Cisco has released software updates and no workarounds are available.
36
60
45
60
57
35
60
60
30
60
35
35
60
60
47
42
55
42
60
60
60
57
57
60
45
60
30
47
60
60
47
30
47
30
35
30