PT-2026-78521 · Cisco · Broadworks
CVE-2026-20320
·
Published
2026-08-19
·
Updated
2026-09-05
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco BroadWorks (affected versions not specified)
Description
An issue in the Open Client Interface (OCI) XML Parser allows an unauthenticated remote attacker to read sensitive configuration information. This occurs because the parser improperly handles XML entries by allowing external entity resolution by default. An attacker can exploit this by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service, potentially enabling the viewing of sensitive filesystem files with the privileges of the Cisco BroadWorks user.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Broadworks