Server-Side Request Forgery Vulnerability in Cisco BroadWorks CommPilot Application
CVE-2022-20951
What is CVE-2022-20951?
A vulnerability in the web-based management interface of Cisco's BroadWorks CommPilot application allows authenticated, remote attackers to execute a server-side request forgery (SSRF) attack. This vulnerability stems from inadequate validation of user-provided input. An attacker can exploit this weakness by sending a specially crafted HTTP request to the web interface, potentially gaining access to confidential information from the BroadWorks server and other devices on the network.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco BroadWorks 24.0 ap375672
Cisco BroadWorks 24.0 ap375655
Cisco BroadWorks 24.0 ap376979
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved