Cisco BroadWorks CommPilot Application Software Cross-Site Scripting Vulnerability
TL;DR 📌
A cross-site scripting (XSS) vulnerability has been identified in the Cisco BroadWorks CommPilot Application Software, which could allow an authenticated attacker to execute arbitrary scripts. The highest CVSS score is 4.8, categorized as Medium severity. No workarounds are available, and users are advised to upgrade to fixed software versions.
What happened 🕵️♂️
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software has been discovered. This flaw allows an authenticated remote attacker to conduct cross-site scripting (XSS) attacks by injecting malicious code into specific pages of the interface. Successful exploitation could enable the attacker to execute arbitrary script code or access sensitive browser-based information. To exploit this vulnerability, the attacker must possess valid administrative credentials.
Affected products 🖥️
The vulnerability affects the following Cisco BroadWorks CommPilot Application Software releases:
- 23.0 (Migrate to a fixed release)
- 24.0 (Fixed in 24.0.2025.05)
- 25.0 (Migrate to a fixed release)
- 26.0 (Fixed in 26.0.2025.05)
Additionally, it impacts earlier versions of the Cisco BroadWorks Application Server and BroadWorks Xtended Services Platform.
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 23.0 | Migrate to a fixed release. | |
| 24.0 | 24.0.2025.05 | |
| 25.0 | Migrate to a fixed release. | |
| 26.0 | 26.0.2025.05 | |
| 1.1 | Changed all instances of BroadWorks Application Delivery Platform to the appropriate deployment options for BroadWorks CommPilot Application. | |
| 1.0 | Initial public release. | |
| Cisco BroadWorks CommPilot Application | 24.0.2025.05 | |
| Cisco BroadWorks CommPilot Application | 26.0.2025.05 | |
| Cisco BroadWorks Application Server | RI.2025.05 | Earlier than RI.2025.05 |
| BroadWorks Xtended Services Platform | RI.2025.08 | Earlier than RI.2025.08 |
Workarounds 🧯
There are no workarounds available for this vulnerability.
Risk in context 🎯
With a CVSS score of 4.8, this vulnerability is rated as Medium severity. The risk is primarily driven by the requirement for authenticated access, which limits exposure but still poses a significant threat if exploited. The absence of workarounds necessitates prompt action to upgrade to fixed software to mitigate potential risks.
Fast facts ⚡
- Vulnerability Type: Cross-Site Scripting (XSS)
- CVSS Score: 4.8 (Medium)
- Exploitation Requirement: Valid administrative credentials
- Workarounds: None available
- Fixed Releases: Available for specific versions
For leadership 🧭
Executive summary. An admin-level user of Cisco BroadWorks CommPilot can plant script that executes in another administrator’s browser session, potentially exposing session data or hijacking that session within the management portal. There is no workaround, so this needs to be scheduled into upgrade planning rather than treated as an emergency given the medium severity and authenticated-only access requirement.
Why it matters:
- Exploitation requires valid administrative credentials to the CommPilot web management interface, so this is a threat from insiders or compromised admin accounts rather than an unauthenticated internet attacker.
- Successful injection lets an attacker execute arbitrary script or access sensitive browser-based information inside the CommPilot portal, which manages BroadWorks Application Server and Xtended Services Platform functions.
- Versions 23.0 and 25.0 have no direct patch and require migration to a fixed release, adding a planning step beyond a simple version bump.
- With no workarounds published, affected BroadWorks Application Server, Xtended Services Platform and CommPilot deployments remain exposed until the upgrade is completed.
Now / Next / Later:
- Now: Identify which BroadWorks CommPilot, Application Server and Xtended Services Platform versions are running in your environment and check them against the fixed-release table.
- Next: Upgrade 24.0 and 26.0 trains to 24.0.2025.05 and 26.0.2025.05 respectively, and move Application Server and Xtended Services Platform to RI.2025.05 and RI.2025.08 or later during your next change window.
- Later: For 23.0 and 25.0 deployments with no direct fix, plan a migration path to a supported, fixed release train and review administrative account controls for the CommPilot interface to limit exposure to credential compromise.