VDB
CVE-2022-20951
CVE-2022-20951
PUBLISHED
CVSS 7.699999809265137 HIGH
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to obtain confidential information from the BroadWorks server and other device on the network. {{value}} ["%7b%7bvalue%7d%7d"])}]]
EPSS 0.52% · 67.3th percentile
Risk Scores
CVSS 3.1
7.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS Score
0.52%
67.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | broadworks_messaging_server | 0 |
| Cisco | Cisco BroadWorks | 24.0 ap375655, 24.0 ap376979, 24.0 ap379112 |
Exploit Intelligence
- cisco-sa-broadworks-ssrf-BJeQfpp (circl)
Timeline
- Nov 3, 2022 CVE Published
- Nov 5, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Jan 30, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 15, 2023 EPSS Score
- Apr 27, 2023 EPSS Score
- Jun 9, 2023 EPSS Score
- Jul 22, 2023 EPSS Score
- Sep 3, 2023 EPSS Score
- Oct 16, 2023 EPSS Score
- Nov 29, 2023 EPSS Score
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-csrf-vgNtTpAs advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-broadworks-ssrf-BJeQfpp technical
- https://nvd.nist.gov/vuln/detail/CVE-2022-20951 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-broadworks-ssrf-BJeQfpp url