VDB

CVE-2023-20216

CVE-2023-20216 PUBLISHED CVSS 4.400000095367432 MEDIUM

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions. There are workarounds that address this vulnerability.

EPSS 0.01% · 2.7th percentile

Risk Scores

CVSS 3.1
4.400000095367432
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.01%
2.7th percentile

Affected Products

VendorProductVersions
ciscobroadworks_execution_server0
ciscobroadworks_database_server0
CiscoCisco BroadWorks*, *, *
ciscobroadworks_network_server0, 0
ciscobroadworks_network_database_server0
ciscobroadworks_xtended_services_platform0, 0
ciscobroadworks_media_server0
ciscobroadworks_application_delivery_platform0
ciscobroadworks_profile_server0, 0
ciscobroadworks_service_control_function_server0
ciscobroadworks_troubleshooting_server0
ciscobroadworks_application_server0, 24.0, 0
ciscobroadworks_network_function_manager0

Exploit Intelligence

Timeline

  • Aug 3, 2023 CVE Published
  • Aug 4, 2023 EPSS Score
  • Sep 7, 2023 EPSS Score
  • Oct 11, 2023 EPSS Score
  • Nov 13, 2023 EPSS Score
  • Dec 17, 2023 EPSS Score
  • Jan 20, 2024 EPSS Score
  • Feb 23, 2024 EPSS Score
  • Mar 28, 2024 EPSS Score
  • Apr 30, 2024 EPSS Score
  • Jun 3, 2024 EPSS Score
  • Jul 7, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›