Permissions, Privileges, and Access Controls in Cisco Systems, Inc products - CVE-2023-20210
Published: July 7, 2023
Vulnerability identifier: #VU78014
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-20210
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local administrator to escalate privileges on the system.
The vulnerability exists due to insufficient input validation by the operating system CLI, which leads to security restrictions bypass and privilege escalation.
Affected software
BroadWorks Application Server
BroadWorks Xtended Services Platform
BroadWorks Database Server
BroadWorks WebRTC Server
BroadWorks Execution Server
BroadWorks Video Server
BroadWorks Messaging Server
BroadWorks Network Database Server
BroadWorks Sharing Server
BroadWorks Network Function Manager
BroadWorks Network Server
BroadWorks Profile Server
BroadWorks Service Control Function Server
BroadWorks Application Delivery Platform
BroadWorks Media Server
BroadWorks Database Troubleshooting Server
BroadWorks Xtended Services Platform
BroadWorks Database Server
BroadWorks WebRTC Server
BroadWorks Execution Server
BroadWorks Video Server
BroadWorks Messaging Server
BroadWorks Network Database Server
BroadWorks Sharing Server
BroadWorks Network Function Manager
BroadWorks Network Server
BroadWorks Profile Server
BroadWorks Service Control Function Server
BroadWorks Application Delivery Platform
BroadWorks Media Server
BroadWorks Database Troubleshooting Server
How to mitigate CVE-2023-20210
Install updates from vendor's website.
BroadWorks Application Server - addressed in versions AP.platform.23.0.1075.ap385266, AP.as.24.0.944.ap385266, Rel_2023.05_1.290
BroadWorks Xtended Services Platform - addressed in versions AP.platform.23.0.1075.ap385266, Rel_2023.05_1.290
BroadWorks Database Server - update to Rel_2023.05_1.290
BroadWorks Execution Server - update to Rel_2023.05_1.290
BroadWorks Network Database Server - update to Rel_2023.05_1.290
BroadWorks Network Function Manager - update to Rel_2023.05_1.290
BroadWorks Network Server - addressed in versions AP.platform.23.0.1075.ap385266, Rel_2023.05_1.290
BroadWorks Profile Server - addressed in versions AP.platform.23.0.1075.ap385266, Rel_2023.05_1.290
BroadWorks Service Control Function Server - update to Rel_2023.05_1.290
BroadWorks Application Delivery Platform - update to Rel_2023.05_1.290
BroadWorks Media Server - update to Rel_2023.05_1.290
BroadWorks Database Troubleshooting Server - update to Rel_2023.05_1.290
BroadWorks Xtended Services Platform - addressed in versions AP.platform.23.0.1075.ap385266, Rel_2023.05_1.290
BroadWorks Database Server - update to Rel_2023.05_1.290
BroadWorks Execution Server - update to Rel_2023.05_1.290
BroadWorks Network Database Server - update to Rel_2023.05_1.290
BroadWorks Network Function Manager - update to Rel_2023.05_1.290
BroadWorks Network Server - addressed in versions AP.platform.23.0.1075.ap385266, Rel_2023.05_1.290
BroadWorks Profile Server - addressed in versions AP.platform.23.0.1075.ap385266, Rel_2023.05_1.290
BroadWorks Service Control Function Server - update to Rel_2023.05_1.290
BroadWorks Application Delivery Platform - update to Rel_2023.05_1.290
BroadWorks Media Server - update to Rel_2023.05_1.290
BroadWorks Database Troubleshooting Server - update to Rel_2023.05_1.290