CVE-2023-20019

Severity
6.1MEDIUM
EPSS
0.8%
top 26.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20

Description

A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

NVDcisco/broadworks_xtended_services_platform< ap.xsp.23.0.1075.ap384344
NVDcisco/broadworks_application_server< ap.as.24.0.944.ap384344
CVEListV5cisco/cisco_broadworks1350 versions+1349

🔴Vulnerability Details

2
GHSA
GHSA-r293-6wjm-x8g7: A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisc2023-01-20
CVEList
CVE-2023-20019: A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisc2023-01-19

📋Vendor Advisories

1
Cisco
Cisco BroadWorks Application Delivery Platform, Application Server, and Xtended Services Platform Cross-Site Scripting Vulnerability2023-01-11
CVE-2023-20019 (MEDIUM CVSS 6.1) | A vulnerability in the web-based ma | cvebase.io