Information disclosure in Cisco BroadWorks Application Server - CVE-2021-1562
Published: July 8, 2021
Cisco BroadWorks Application Server
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper input validation and authorization of specific commands that a user can execute within the XSI-Actions interface. A remote authenticated attacker can gain unauthorized access to sensitive information on the system.