PT-2021-2973 · Broadsoft · Broadworks Messaging Server

Published

2021-05-05

·

Updated

2021-05-14

·

CVE-2021-1530

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions BroadWorks Messaging Server (affected versions not specified)
Description The issue is related to the improper restriction of XML external entity references in the web-based management interface of the BroadWorks Messaging Server. This could allow a remote attacker to gain unauthorized access to sensitive information or cause a denial of service condition. The vulnerability is due to the improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this by uploading a crafted XML file containing references to external entities, potentially allowing them to retrieve files from the local system or consume available resources, leading to a partial denial of service condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02560
CVE-2021-1530

Affected Products

Broadworks Messaging Server