🎁-time: Here you go two @Cisco BroadWorks CommPilot Application Software vulnerabilities which our team (@smaury92, @zi0Black, @Th3Zer0) found during an engagement for one of our customers.
CVE-2022-20951: Unauthenticated SSRF
CVE-2022-20958: Authenticated RCE
Links in the 🧵👇🏿
@WarConPL V edition was a blast. With @h0wlu we are now summoning the proliferation of similar offensive security private events across EU. Make them happen!
May WarCon stay in your memories.
Ave WarCon, morituri te salutant!
🐐🐐🐐🐐🐐🐐
This was my first time at an IT sec conf, and I'm very glad it was at @WarConPL. It's been a truly amazing experience, huge props to @antisnatchor and @h0wlu for organizing it!