Lucene search

K
ciscoCiscoCISCO-SA-BW-PRIVESC-YW4EKRXW
HistoryJul 05, 2023 - 4:00 p.m.

Cisco BroadWorks Privilege Escalation Vulnerability

2023-07-0516:00:00
tools.cisco.com
9
cisco
broadworks
privilege escalation
vulnerability
authenticate
local attacker
elevate privileges
crafted command
operating system
insufficient input validation
software update
administrative privileges
security advisory

0.0004 Low

EPSS

Percentile

5.1%

A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device.

The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-privesc-yw4ekrXW [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-privesc-yw4ekrXW”]

Affected configurations

Vulners
Node
ciscobroadworksMatchany
OR
ciscobroadworksMatchany
CPENameOperatorVersion
cisco broadworkseqany
cisco broadworkseqany

0.0004 Low

EPSS

Percentile

5.1%

Related for CISCO-SA-BW-PRIVESC-YW4EKRXW