Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data

Abinaya
4 hours ago
8 Visninger
0 Kommentarer
Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data

Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to read sensitive configuration data and files from affected systems. Tracked as CVE-2026-20320, the issue carries a CVSS score of 7.5 and affects several components of the BroadWorks platform. The vulnerability, identified in the Open Client Interface XML Parser, is classified as CWE-611, or improper restriction of XML external entity reference. Cisco published the advisory, cisco-sa-bworks-xxe-uwUd7CEt, on August 19, 2026. Cisco said the flaw exists because the affected XML parser allows external entity resolution by default. When XML input is processed,...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!