Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-20951
HistoryNov 04, 2022 - 6:15 p.m.

Server side request forgery (ssrf)

2022-11-0418:15:00
PRIOn knowledge base
www.prio-n.com
6
server-side request forgery
cisco broadworks
remote attacker
http request
insufficient validation
network security

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.4%

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to obtain confidential information from the BroadWorks server and other device on the network.

{{value}} [“%7b%7bvalue%7d%7d”])}]]

CPENameOperatorVersion
broadworks_messaging_serverlt23.0

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.4%

Related for PRION:CVE-2022-20951