CVE Vulnerabilities

CVE-2021-34785

Improper Authentication

Published: Sep 09, 2021 | Modified: Nov 07, 2023
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Broadworks_commpilot_application_software Cisco 22.0 (including) 22.0.2021.09 (excluding)
Broadworks_commpilot_application_software Cisco 23.0 (including) 23.0.2021.09 (excluding)
Broadworks_commpilot_application_software Cisco 24.0 (including) 24.0.2021.09 (excluding)

Potential Mitigations

References