CVE-2021-1530 is an XML External Entity (XXE) vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software. An authenticated, remote attacker can exploit this by uploading a crafted XML file. This allows for sensitive information disclosure from the local system or a partial denial of service by consuming system resources. Rated 7.1 HIGH CVSS, it has low attack complexity and requires no user interaction. Currently, there is no known public exploit code, active exploitation, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
22.0CPE matchmatch criteria | cpe:2.3:a:cisco:broadworks_messaging_server:22.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.