CVE Vulnerabilities

CVE-2021-34785

Unverified Password Change

Published: Sep 09, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Affected Software

NameVendorStart VersionEnd Version
Broadworks_commpilot_application_softwareCisco22.0 (including)22.0.2021.09 (excluding)
Broadworks_commpilot_application_softwareCisco23.0 (including)23.0.2021.09 (excluding)
Broadworks_commpilot_application_softwareCisco24.0 (including)24.0.2021.09 (excluding)

Potential Mitigations

References