Absolute Path Traversal in BroadWorks CommPilot Application Software - CVE-2022-20951
Published: November 4, 2022 / Updated: December 21, 2022
BroadWorks CommPilot Application Software
Cisco Systems, Inc
Description
The vulnerability allows a remote user to execute arbitrary commands on the system.
The vulnerability exists due to insufficient validation of user-supplied input in the web-based management interface. A remote authenticated user can send a specially crafted HTTP request and execute arbitrary OS commands on the device as the bworks user.