CVE-2021-34786

MEDIUM

Cisco BroadWorks CommPilot Application Software 22.0-22.0.2021.09 - Authenticated Unverified Password Change

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0102
EPSS Percentile 60.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287 CWE-620
Status published
Products (1)
cisco/broadworks_commpilot_application_software 22.0 - 22.0.2021.09
Published Sep 09, 2021
Tracked Since Feb 18, 2026