MEDIUM · 6.0

CVE-2023-20210

A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validat...

Vulnerability Description

A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.

CVSS Score

6.0

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
CiscoBroadworks Application Delivery Platform Firmware23.0
CiscoBroadworks Application Delivery Platform-
CiscoBroadworks Application Server Firmware23.0
CiscoBroadworks Application Server-
CiscoBroadworks Database Server Firmware23.0
CiscoBroadworks Database Server-
CiscoBroadworks Database Troubleshooting Server Firmware23.0
CiscoBroadworks Database Troubleshooting Server-
CiscoBroadworks Execution Server Firmware23.0
CiscoBroadworks Execution Server-
CiscoBroadworks Media Server Firmware23.0
CiscoBroadworks Media Server-
CiscoBroadworks Messaging Server Firmware23.0
CiscoBroadworks Messaging Server-
CiscoBroadworks Network Database Server Firmware23.0
CiscoBroadworks Network Database Server-
CiscoBroadworks Network Function Manager Firmware23.0
CiscoBroadworks Network Function Manager-
CiscoBroadworks Network Server Firmware23.0
CiscoBroadworks Network Server-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-20210?

CVE-2023-20210 is a vulnerability with a CVSS score of 6.0 (MEDIUM). A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validat...

How severe is CVE-2023-20210?

CVE-2023-20210 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-20210?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Broadworks Application Delivery Platform Firmware, Cisco Broadworks Application Delivery Platform, Cisco Broadworks Application Server Firmware, Cisco Broadworks Application Server, Cisco Broadworks Database Server Firmware.