Lucene search

K
nvd[email protected]NVD:CVE-2023-20216
HistoryAug 03, 2023 - 10:15 p.m.

CVE-2023-20216

2023-08-0322:15:11
CWE-269
CWE-732
web.nvd.nist.gov
cisco broadworks
privilege management
vulnerability
local attacker
elevated privileges
user role permissions
crafted commands
workarounds

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system.

This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions.

There are workarounds that address this vulnerability.

Affected configurations

NVD
Node
ciscobroadworks_application_delivery_platformRange<ri.2023.05
OR
ciscobroadworks_application_serverRange<23.0.2023.05-
OR
ciscobroadworks_application_serverRange<2023.05release_independent
OR
ciscobroadworks_application_serverRange24.024.0.2023.05-
OR
ciscobroadworks_database_serverRange<2023.05release_independent
OR
ciscobroadworks_execution_serverRange<2023.05release_independent
OR
ciscobroadworks_media_serverRange<2023.05release_independent
OR
ciscobroadworks_network_database_serverRange<2023.05release_independent
OR
ciscobroadworks_network_function_managerRange<2023.05release_independent
OR
ciscobroadworks_network_serverRange<23.0.2023.05-
OR
ciscobroadworks_network_serverRange<2023.05release_independent
OR
ciscobroadworks_profile_serverRange<23.0.2023.05-
OR
ciscobroadworks_profile_serverRange<2023.05release_independent
OR
ciscobroadworks_service_control_function_serverRange<2023.05release_independent
OR
ciscobroadworks_troubleshooting_serverRange<2023.06release_independent
OR
ciscobroadworks_xtended_services_platformRange<23.0.2023.05-
OR
ciscobroadworks_xtended_services_platformRange<2023.05release_independent

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

5.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for NVD:CVE-2023-20216