Impact
The vulnerability arises from missing authentication checks in the web‑based management interface of Cisco BroadWorks CommPilot Application Software. An attacker who already has a low‑privilege authenticated session can send a crafted HTTP request to bypass authorization and modify configuration settings on specific pages. This flaw is categorized as an authorization bypass (CWE‑863) and results in unauthorized configuration changes.
Affected Systems
Affected systems are devices running Cisco BroadWorks CommPilot Application Software from Cisco. The advisory does not list specific version ranges, so all versions of the CommPilot application software that are not yet patched are potentially vulnerable. The flaw applies to the web interface exposed for remote management.
Risk and Exploitability
The CVSS score of 6.5 denotes medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not flagged in CISA’s KEV catalog. Exploitation requires remote authenticated access with low privileges, which many internal users have, making the risk moderate. Successful exploitation would grant the attacker control over device configuration, potentially disrupting services or enabling further attacks.
OpenCVE Enrichment