Friday, December 6, 2024
HomeCiscoCisco BroadWorks Application Software Flaw Let Attackers conduct XSS Attack

Cisco BroadWorks Application Software Flaw Let Attackers conduct XSS Attack

Published on

SIEM as a Service

Cisco released a fix for the medium impact vulnerability found on CommPilot Application Software, allowing cross-site scripting against the user interface.

The Cisco BroadWorks CommPilot Application allows authenticated users to upload configuration files on the platform.

The lack of file validation and broken access control on the vulnerable upload servlet allows any authenticated user to upload a file, which could be abused to run arbitrary code on the server.

- Advertisement - SIEM as a Service

Cisco’s BroadWorks Application Delivery Platform, BroadWorks Application Server (AS), and BroadWorks Xtended Services Platform (XSP) are affected by this vulnerability.

Vulnerability in detail:

The latest update for the Cisco BroadWorks CommPilot Application Software Cross-Site Scripting Vulnerability was published on August 30 by Cisco.

The web-based management interface does not properly validate user-supplied input, which lets an attacker exploit this vulnerability by persuading a user to click a crafted link. 

A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

They have released software updates that address this vulnerability, but no workarounds address it.

The Cisco Product Security Incident Response Team (PSIRT) validates only the affected and fixed-release information that is documented in this advisory.

Before upgrading devices, Cisco recommends its customers ensure that the memory and current hardware and software configurations will continue to be supported properly by the new release.

Fixed Release:

Cisco BroadWorks Application Delivery Platform with CommPilot-25, CommPilot-24, and CommPilot-23 ReleaseFirst Fixed Release
Release Independent (RI)RI 2023.06
Cisco BroadWorks Application Server Software ReleaseFirst Fixed Release
Earlier than 23.0Migrate to a fixed release.
23.0AP.as.23.0.1075.ap385295.Linux-x86_64.zip
24.0AP.as.24.0.944.ap385295.Linux-x86_64.zip
Release Independent (RI)RI 2023.06
Cisco BroadWorks Xtended Services Platform Software ReleaseFirst Fixed Release
Earlier than 23.0Migrate to a fixed release.
23.0AP.xsp.23.0.1075.ap385295.Linux-x86_64.zip
Release Independent (RI)RI 2023.08

Keep informed about the latest Cyber Security News by following us on Google NewsLinkedinTwitter, and Facebook.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Top Five Industries Most Frequently Targeted by Phishing Attacks

Researchers analyzed phishing attacks from Q3 2023 to Q3 2024 and identified the top...

Russian BlueAlpha APT Exploits Cloudflare Tunnels to Distribute Custom Malware

BlueAlpha, a Russian state-sponsored group, is actively targeting Ukrainian individuals and organizations by using...

Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication

Secret Blizzard, a Russian threat actor, has infiltrated 33 command-and-control (C2) servers belonging to...

Sophisticated Celestial Stealer Targets Browsers to Steal Login Credentials

Researchers discovered Celestial Stealer, a JavaScript-based MaaS infostealer targeting Windows systems that, evading detection...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Top Five Industries Most Frequently Targeted by Phishing Attacks

Researchers analyzed phishing attacks from Q3 2023 to Q3 2024 and identified the top...

Russian BlueAlpha APT Exploits Cloudflare Tunnels to Distribute Custom Malware

BlueAlpha, a Russian state-sponsored group, is actively targeting Ukrainian individuals and organizations by using...

Russian Hackers Hijacked Pakistani Actor Servers For C2 Communication

Secret Blizzard, a Russian threat actor, has infiltrated 33 command-and-control (C2) servers belonging to...