Tuesday, April 15, 2025
HomeCiscoCisco Webex for BroadWorks Flaw Opens Door for Attackers to Access Credentials

Cisco Webex for BroadWorks Flaw Opens Door for Attackers to Access Credentials

Published on

SIEM as a Service

Follow Us on Google News

Cisco Systems has disclosed a security vulnerability in its Webex for BroadWorks unified communications platform that could allow attackers to intercept sensitive credentials and user data under specific configurations.

The flaw, tracked as CSCwo20742 and classified as a low-severity issue, impacts organizations using Release 45.2 of the software in Windows-based environments, prompting Cisco to release configuration-based fixes and recommend immediate application restarts.

Vulnerability Mechanics and Exploitation Risks

The vulnerability stems from insecure Session Initiation Protocol (SIP) transport configurations, which expose authentication headers containing user credentials during communication between clients and servers.

- Advertisement - Google News

SIP, a signaling protocol widely used for voice and video calls, transmits metadata in plaintext unless encrypted.

In affected deployments, attackers could intercept these headers via man-in-the-middle (MitM) attacks, potentially gaining unauthorized access to systems by impersonating legitimate users.

A related issue exacerbates the risk: authenticated users with access to client or server logs could extract credentials stored in plaintext.

This dual exposure vector increases the likelihood of credential theft, particularly in hybrid cloud or on-premises deployments where Windows servers are prevalent.

While Cisco has not observed active exploitation in the wild, the company warns that the flaw’s low complexity and lack of required privileges make it an attractive target for opportunistic attacks.

Affected Systems and Mitigation Strategies

The vulnerability exclusively impacts Cisco Webex for BroadWorks Release 45.2 running on Windows servers. Hybrid deployments combining on-premises and cloud infrastructure are also at risk, while Linux or macOS environments remain unaffected.

Cisco has automatically deployed configuration updates to enforce secure SIP transport protocols like TLS and SRTP, but administrators must restart their applications to activate these changes.

For organizations unable to implement the patch immediately, Cisco recommends manually configuring SIP communication to use encryption protocols.

This workaround prevents header interception but requires administrators to verify compatibility with existing telephony infrastructure.

The company further advises credential rotation for all user accounts associated with Webex for BroadWorks to mitigate potential breaches resulting from prior exposure.

This incident highlights persistent risks in legacy communication protocols like SIP, which were not designed with modern encryption standards.

Analysts note that 32% of enterprise VoIP systems still operate unencrypted SIP trunks, per 2024 data from the Telecommunications Industry Association.

Cisco’s rapid patch deployment reflects growing industry pressure to address vulnerabilities in hybrid work tools, which have become critical infrastructure for global businesses since the pandemic.

This disclosure follows a 17% year-over-year increase in VoIP-related vulnerabilities reported in 2024, underscoring the need for rigorous protocol hardening in enterprise communication ecosystems.

As hybrid work models persist, maintaining secure transport layers remains paramount to thwarting credential-based attacks.

Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Microsoft Teams File Sharing Unavailable Due to Unexpected Outage

Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due...

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...

New ‘Waiting Thread Hijacking’ Malware Technique Evades Modern Security Measures

Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking"...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Microsoft Teams File Sharing Unavailable Due to Unexpected Outage

Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due...

Cloud Misconfigurations – A Leading Cause of Data Breaches

Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost...

Security Awareness Metrics That Matter to the CISO

Security awareness has become a critical component of organizational defense strategies, particularly as companies...