CVE-2021-1530 vulnerability in Cisco Products
Published on May 6, 2021
Cisco BroadWorks Messaging Server XML External Entity Injection Vulnerability
A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS) condition on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by uploading a crafted XML file that contains references to external entities. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a partial DoS condition on an affected system. There are workarounds that address this vulnerability.
Vulnerability Analysis
CVE-2021-1530 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity, and a small impact on availability.
Weakness Type
What is a XXE Vulnerability?
The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVE-2021-1530 has been classified to as a XXE vulnerability or weakness.
Products Associated with CVE-2021-1530
stack.watch emails you whenever new vulnerabilities are published in Cisco Broadworks Messaging Server or Cisco Broadworks. Just hit a watch button to start following.
Affected Versions
Cisco BroadWorks Version n/a is affected by CVE-2021-1530Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.