Kryptovalutaticker:
sysadmin från Cyber Security News

Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data

Abinaya
4 hours ago
11 Visningar
0 Kommentarer
Cisco External Entity Injection Vulnerability Allows Attackers to Read Sensitive Data

Cisco has released security updates for a high-severity XML External Entity injection vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to read sensitive configuration data and files from affected systems. Tracked as CVE-2026-20320, the issue carries a CVSS score of 7.5 and affects several components of the BroadWorks platform. The vulnerability, identified in the Open Client Interface XML Parser, is classified as CWE-611, or improper restriction of XML external entity reference. Cisco published the advisory, cisco-sa-bworks-xxe-uwUd7CEt, on August 19, 2026. Cisco said the flaw exists because the affected XML parser allows external entity resolution by default. When XML input is processed,...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!