Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco BroadWorks Application Delivery Platform. This issue allows an authenticated, remote attacker to conduct XSS attacks against users of the interface. The vulnerability arises from inadequate validation of user-supplied input, enabling attackers to inject malicious code into specific pages. Exploitation of this vulnerability could result in the execution of arbitrary scripts in the context of the affected interface or the access of sensitive browser-based information. To exploit this vulnerability, an attacker must possess valid administrative credentials.

Impact

Exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the affected user interface, potentially leading to the execution of malicious actions or the theft of sensitive information accessible through the user's browser.

Remediation

Users can upgrade to Cisco BroadWorks Application Delivery Platform release RI.2025.05 or later to address this vulnerability. For guidance on upgrading, consult the Cisco Security Vulnerability Policy or contact the Cisco Technical Assistance Center (TAC).

Added: Jul 2, 2025, 5:21 PM
Updated: Jul 2, 2025, 5:21 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
3.5
exploitability
4.1
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.