CVE-2023-20216
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions. There are workarounds that address this vulnerability.
EPSS 0.01% · 2.7th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | broadworks_execution_server | 0 |
| cisco | broadworks_database_server | 0 |
| Cisco | Cisco BroadWorks | *, *, * |
| cisco | broadworks_network_server | 0, 0 |
| cisco | broadworks_network_database_server | 0 |
| cisco | broadworks_xtended_services_platform | 0, 0 |
| cisco | broadworks_media_server | 0 |
| cisco | broadworks_application_delivery_platform | 0 |
| cisco | broadworks_profile_server | 0, 0 |
| cisco | broadworks_service_control_function_server | 0 |
| cisco | broadworks_troubleshooting_server | 0 |
| cisco | broadworks_application_server | 0, 24.0, 0 |
| cisco | broadworks_network_function_manager | 0 |
Exploit Intelligence
- cisco-sa-bw-priv-esc-qTgUZOsQ (circl)
Timeline
- Aug 3, 2023 CVE Published
- Aug 4, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
- Oct 11, 2023 EPSS Score
- Nov 13, 2023 EPSS Score
- Dec 17, 2023 EPSS Score
- Jan 20, 2024 EPSS Score
- Feb 23, 2024 EPSS Score
- Mar 28, 2024 EPSS Score
- Apr 30, 2024 EPSS Score
- Jun 3, 2024 EPSS Score
- Jul 7, 2024 EPSS Score