• News/
  • https://www.bleepingcomputer.com/news/security/cisco-warns-of-webex-for-broadworks-flaw-exposing-credentials/

Cisco warns of Webex for BroadWorks flaw exposing credentials

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 4, 2025
·
Updated

Cisco warned customers today of a vulnerability in Webex for BroadWorks that could let unauthenticated attackers access credentials remotely. Webex for BroadWorks integrates Cisco Webex's video conferencing and collaboration features with the BroadWorks unified communications platform. While the company has yet to assign a CVE ID to track this security issue, Cisco says in a Tuesday security advisory that it already pushed a configuration change to address the flaw and advised customers to restart their Cisco Webex app to get the fix. "A low-severity vulnerability in Cisco Webex for BroadWorks Release 45.2 could allow an unauthenticated, remote attacker to access data and credentials if unsecure transport is configured for the SIP communication," Cisco explained. "A related issue could allow an authenticated user to access credentials in plain text in the client and server logs. A malicious actor could exploit this vulnerability and the related issue to access data and credentials and impersonate the user." The vulnerability is caused by sensitive information exposed in the SIP headers and only affects Cisco BroadWorks (on-premises) and Cisco Webex for BroadWorks (hybrid cloud/on-premises) instances running in Windows environments. The company advises admins to configure secure transport for SIP communication to encrypt data in transit as a temporary workaround until the configuration change reaches their environment. "Cisco also recommends rotating credentials to protect ag...

Read full article

Affected Software

3 affected components
Cisco Webex for BroadWorks=45.2
Cisco BroadWorks
Cisco Webex for BroadWorks=45.2
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a vulnerability in Cisco Webex for BroadWorks that allows unauthorized access to user credentials.

2

What security implications are discussed?

The vulnerability could enable unauthenticated attackers to remotely access sensitive user credentials.

3

What products or software are affected?

The affected products are Cisco Webex for BroadWorks and Cisco BroadWorks.

4

What should organizations using these products do in response to the vulnerability?

Organizations should review Cisco's security advisories and apply any available patches or mitigations.

5

When was the vulnerability disclosed?

The vulnerability was disclosed by Cisco on March 4, 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203