CVE-2023-20216
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions. There are workarounds that address this vulnerability.
Published:Aug 3, 2023
Last Modified:Nov 21, 2024
EPS:Aug 3, 2023
EPSS Score:0.00012
CVSS Score:4.4
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Broadworks Application Delivery Platform
Cisco
Broadworks Application Delivery Platform
Vendor
Cisco
Product
Broadworks Application Server
Cisco
Broadworks Application Server
Vendor
Cisco
Product
Broadworks Database Server
Cisco
Broadworks Database Server
Vendor
Cisco
Product
Broadworks Execution Server
Cisco
Broadworks Execution Server
Vendor
Cisco
Product
Broadworks Media Server
Cisco
Broadworks Media Server
Vendor
Cisco
Product
Broadworks Network Database Server
Cisco
Broadworks Network Database Server
Vendor
Cisco
Product
Broadworks Network Function Manager
Cisco
Broadworks Network Function Manager
Vendor
Cisco
Product
Broadworks Network Server
Cisco
Broadworks Network Server
Vendor
Cisco
Product
Broadworks Profile Server
Cisco
Broadworks Profile Server
Vendor
Cisco
Product
Broadworks Service Control Function Server
Cisco
Broadworks Service Control Function Server
Vendor
Cisco
Product
Broadworks Troubleshooting Server
Cisco
Broadworks Troubleshooting Server
Vendor
Cisco
Product
Broadworks Xtended Services Platform
Cisco
Broadworks Xtended Services Platform
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
