Full Report
Cisco security advisory (AV26-834)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Cisco BroadWorks and Crosswork Products
## CVE Details
*Note: The primary technical flaw highlighted in this advisory is the BroadWorks XXE vulnerability. The Hardening Releases address multiple unspecified vulnerabilities through platform updates.*
- **CVE ID:** CVE-2024-20464 (BroadWorks)
- **CVSS Score:** 6.3 (Medium)
- **CWE:** CWE-611 (Improper Restriction of XML External Entity Reference)
## Affected Systems
- **BroadWorks Products (Prior to RI.2026.07):**
- Application Delivery Platform
- Application Server
- Profile Server
- Xtended Services Platform
- **Cisco Crosswork (Prior to 7.2.1-SP):**
- Crosswork Planning
- Crosswork Data Gateway
- Crosswork Network Controller
- **Cisco Secure Workload:**
- Version 3.10 (Prior to 3.10.9.1)
- Version 4.0 (Prior to 4.0.4.16)
## Vulnerability Description
The critical vulnerability identified (CVE-2024-20464) is an **Out-of-Band (OOB) Blind XML External Entity (XXE) Injection** in Cisco BroadWorks. This flaw occurs due to improper validation of user-supplied XML input. An attacker can send a crafted XML file containing a reference to an external entity. Because the application processes this entity without sufficient validation, it can be leveraged to disclose internal files or perform SSRF (Server-Side Request Forgery) to probe internal services.
The Crosswork and Secure Workload advisories refer to "Security Hardening" releases, which typically bundle multiple security improvements, library updates, and fixes for underlying OS vulnerabilities.
## Exploitation
- **Status:** Not exploited (No reports of active exploitation at the time of advisory)
- **Complexity:** Medium
- **Attack Vector:** Network (Unauthenticated for BroadWorks XXE)
## Impact
- **Confidentiality:** High (Ability to read arbitrary files from the server)
- **Integrity:** None
- **Availability:** Low (Potential for service disruption via resource exhaustion)
## Remediation
### Patches
Cisco has released software updates to address these vulnerabilities. Users are advised to migrate to the following versions or later:
- **BroadWorks:** Update to version **RI.2026.07**
- **Cisco Crosswork:** Update to version **7.2.1-SP**
- **Cisco Secure Workload 3.10:** Update to **3.10.9.1**
- **Cisco Secure Workload 4.0:** Update to **4.0.4.16**
### Workarounds
- There are no documented workarounds for these vulnerabilities. System hardening and immediate patching are the recommended courses of action.
## Detection
- **Indicators of Compromise:** Monitor network traffic for unusual outbound requests (OOB) to unknown external IP addresses from BroadWorks servers.
- **Detection Methods:** Review system logs for XML processing errors or unexpected file access patterns on the Application Server and Profile Server.
## References
- **Cisco BroadWorks XXE Advisory:** hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt
- **Cisco Crosswork Hardening:** hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh
- **Cisco Secure Workload Hardening:** hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP
- **General Cisco Advisories:** hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/publicationListing[.]x