CVE Vulnerabilities

CVE-2021-34786

Unverified Password Change

Published: Sep 09, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Affected Software

Name Vendor Start Version End Version
Broadworks_commpilot_application_software Cisco 22.0 (including) 22.0.2021.09 (excluding)
Broadworks_commpilot_application_software Cisco 23.0 (including) 23.0.2021.09 (excluding)
Broadworks_commpilot_application_software Cisco 24.0 (including) 24.0.2021.09 (excluding)

Potential Mitigations

References