CVE-2023-20210
published 2023-07-12CVE-2023-20210: A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The…
PriorityP432medium6CVSS 3.1
AVLACLPRHUINSUCHIHAN
EPSS
0.20%
10.4th percentile
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device.
The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.
Affected
9245 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | broadworks | — | — |
| cisco | broadworks_application_delivery_platform_firmware | — | — |
| cisco | broadworks_application_delivery_platform_firmware | — | — |
| cisco | broadworks_application_delivery_platform_firmware | — | — |
| cisco | broadworks_application_server_firmware | — | — |
| cisco | broadworks_application_server_firmware | — | — |
| cisco | broadworks_application_server_firmware | — | — |
| cisco | broadworks_database_server_firmware | — | — |
| cisco | broadworks_database_server_firmware | — | — |
| cisco | broadworks_database_server_firmware | — | — |
| cisco | broadworks_database_troubleshooting_server_firmware | — | — |
| cisco | broadworks_database_troubleshooting_server_firmware | — | — |
| cisco | broadworks_database_troubleshooting_server_firmware | — | — |
| cisco | broadworks_execution_server_firmware | — | — |
| cisco | broadworks_execution_server_firmware | — | — |
| cisco | broadworks_execution_server_firmware | — | — |
| cisco | broadworks_media_server_firmware | — | — |
| cisco | broadworks_media_server_firmware | — | — |
| cisco | broadworks_media_server_firmware | — | — |
| cisco | broadworks_messaging_server_firmware | — | — |
| cisco | broadworks_messaging_server_firmware | — | — |
| cisco | broadworks_messaging_server_firmware | — | — |
| cisco | broadworks_network_database_server_firmware | — | — |
| cisco | broadworks_network_database_server_firmware | — | — |
| cisco | broadworks_network_database_server_firmware | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
vendor_cisco6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco BroadWorks Privilege Escalation Vulnerability
vendor_cisco·2023-07-05·CVSS 6.0
CVE-2023-20210 [MEDIUM] CWE-250 Cisco BroadWorks Privilege Escalation Vulnerability
Cisco BroadWorks Privilege Escalation Vulnerability
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device.
The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/securi
Cisco
Cisco BroadWorks Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2023-20210 Cisco BroadWorks Privilege Escalation Vulnerability
CVE-2023-20210: Cisco BroadWorks Privilege Escalation Vulnerability
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-250, CWE-250
Bug IDs: CSCwe83127
GHSA
GHSA-4hhj-h38j-ccw8: A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device
ghsa_unreviewed·2023-07-12
CVE-2023-20210 [MEDIUM] CWE-250 GHSA-4hhj-h38j-ccw8: A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device.
The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-12
Published