CVE-2021-1530 - CVE House
Back to Database
Status published Medium CVE-2021-1530

Cisco BroadWorks Messaging Server XML External Entity Injection Vulnerability

Vulnerability Description

A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS) condition on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by uploading a crafted XML file that contains references to external entities. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a partial DoS condition on an affected system. There are workarounds that address this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-1530

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cisco BroadWorks
Vulnerable Versions:
Unknown

Timeline

Official Publish: May 6th, 2021
Last Modified: November 8th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Weaknesses (CWE)