Input validation error in Cisco BroadWorks Application Delivery Platform Device Management and Cisco BroadWorks Xtended Services Platform - CVE-2023-20020
Published: January 12, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the Device Management Servlet application when parsing HTTP requests. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
Cisco BroadWorks Xtended Services Platform
How to mitigate CVE-2023-20020
Cisco BroadWorks Xtended Services Platform - addressed in versions AP.xsp.23.0.1075.ap384245, AP.platform.23.0.1075.ap384245