Description
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device.

The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.
Published: 2023-07-12
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-24389 A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.
History

No history.

Subscriptions

Cisco Broadworks Application Delivery Platform Broadworks Application Delivery Platform Firmware Broadworks Application Server Broadworks Application Server Firmware Broadworks Database Server Broadworks Database Server Firmware Broadworks Database Troubleshooting Server Broadworks Database Troubleshooting Server Firmware Broadworks Execution Server Broadworks Execution Server Firmware Broadworks Media Server Broadworks Media Server Firmware Broadworks Messaging Server Broadworks Messaging Server Firmware Broadworks Network Database Server Broadworks Network Database Server Firmware Broadworks Network Function Manager Broadworks Network Function Manager Firmware Broadworks Network Server Broadworks Network Server Firmware Broadworks Profile Server Broadworks Profile Server Firmware Broadworks Service Control Function Server Broadworks Service Control Function Server Firmware Broadworks Sharing Server Broadworks Sharing Server Firmware Broadworks Video Server Broadworks Video Server Firmware Broadworks Webrtc Server Broadworks Webrtc Server Firmware Broadworks Xtended Services Platform Broadworks Xtended Services Platform Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-08-02T09:05:36.936Z

Reserved: 2022-10-27T18:47:50.367Z

Link: CVE-2023-20210

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-07-12T14:15:09.873

Modified: 2024-11-21T07:40:51.007

Link: CVE-2023-20210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses