Impact
A vulnerability exists in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks that allows external entity resolution by default, which can be exploited as an XML External Entity (XXE) flaw. An attacker who does not need to authenticate can send a specially crafted XML payload to the OCI–Provisioning service, causing the server to read arbitrary files from the filesystem with the privileges of the BroadWorks service account. The disclosed data could include sensitive configuration files, making this a significant confidentiality issue. The weakness is identified as CWE‑611 and carries a CVSS score of 7.5, indicating a high severity for information disclosure.
Affected Systems
All Cisco BroadWorks deployments that expose the Open Client Interface (OCI) are affected. The advisory does not specify particular product versions, so any BroadWorks installation using the default OCI XML parser configuration should be considered vulnerable until Cisco releases a patch or configuration guidance.
Risk and Exploitability
The likely attack vector is remote network access to the OCI–Provisioning (OCI–P) endpoint; an unauthenticated attacker can trigger the flaw by sending a crafted XML message over the network. The CVSS base score reflects a large confidentiality impact, but the EPSS score of less than 1% indicates that documented exploitation is currently rare. The absence from the CISA KEV catalog further suggests that widespread exploitation is unlikely at present. Nevertheless, because the exploit requires only network connectivity and no user credential, the risk remains high for exposed OCI services, especially for systems that allow unrestricted external access.
OpenCVE Enrichment