THREAT OPS › Threat News › Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability
Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability
<p>A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system.</p> <p>This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted
Indicators of compromise
- CVE-2026-20320cve