cbcvebase.
CVE-2023-20210
published 2023-07-12

CVE-2023-20210: A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The…

PriorityP432medium6CVSS 3.1
AVLACLPRHUINSUCHIHAN
EPSS
0.20%
10.4th percentile
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.

Affected

9245 ranges· showing 25
VendorProductVersion rangeFixed in
ciscobroadworks
ciscobroadworks_application_delivery_platform_firmware
ciscobroadworks_application_delivery_platform_firmware
ciscobroadworks_application_delivery_platform_firmware
ciscobroadworks_application_server_firmware
ciscobroadworks_application_server_firmware
ciscobroadworks_application_server_firmware
ciscobroadworks_database_server_firmware
ciscobroadworks_database_server_firmware
ciscobroadworks_database_server_firmware
ciscobroadworks_database_troubleshooting_server_firmware
ciscobroadworks_database_troubleshooting_server_firmware
ciscobroadworks_database_troubleshooting_server_firmware
ciscobroadworks_execution_server_firmware
ciscobroadworks_execution_server_firmware
ciscobroadworks_execution_server_firmware
ciscobroadworks_media_server_firmware
ciscobroadworks_media_server_firmware
ciscobroadworks_media_server_firmware
ciscobroadworks_messaging_server_firmware
ciscobroadworks_messaging_server_firmware
ciscobroadworks_messaging_server_firmware
ciscobroadworks_network_database_server_firmware
ciscobroadworks_network_database_server_firmware
ciscobroadworks_network_database_server_firmware

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
vendor_cisco6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.