CVE-2021-34786
published 2021-09-09CVE-2021-34786: Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or…
PriorityP428medium4.9CVSS 3.1
AVNACLPRHUINSUCNIHAN
EPSS
1.02%
59.5th percentile
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | broadworks_commpilot_application | — | — |
| cisco | broadworks_commpilot_application_software | >= 22.0 < 22.0.2021.09 | 22.0.2021.09 |
| cisco | broadworks_commpilot_application_software | >= 23.0 < 23.0.2021.09 | 23.0.2021.09 |
| cisco | broadworks_commpilot_application_software | >= 24.0 < 24.0.2021.09 | 24.0.2021.09 |
| cisco | cisco_broadworks | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco BroadWorks CommPilot Application Software Vulnerabilities
vendor_cisco·2021-09-08·CVSS 6.5
CVE-2021-34785 [MEDIUM] CWE-620 Cisco BroadWorks CommPilot Application Software Vulnerabilities
Cisco BroadWorks CommPilot Application Software Vulnerabilities
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
For more information about these vulnerabilities, see the Details section of this advisory.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-broadworks-dJ9JT67N
Cisco
Cisco BroadWorks CommPilot Application Software Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-34786 Cisco BroadWorks CommPilot Application Software Vulnerabilities
CVE-2021-34786: Cisco BroadWorks CommPilot Application Software Vulnerabilities
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.1
CWE: CWE-620, CWE-620
Bug IDs: CSCvz32610, CSCvz32611, CSCvz32611, CSCvz32610
GHSA
GHSA-89qr-gmvh-jqf2: Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user acc
ghsa_unreviewed·2022-05-24
CVE-2021-34786 [MEDIUM] CWE-287 GHSA-89qr-gmvh-jqf2: Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user acc
Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-09
Published