Vulnerability Details CVE-2023-20216
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system.
This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions.
There are workarounds that address this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 1.1%
CVSS Severity
CVSS v3 Score 4.4
Products affected by CVE-2023-20216
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:23.0.2024.01
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:24.0.2023.01
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:24.0.2023.10
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2020.07
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2020.10
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2020.11
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2020.12
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.01
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.02
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.03
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.04
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.05
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.06
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.07
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.08
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.09
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.10
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.11
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2021.12
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.01
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.02
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.03
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.04
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.05
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.06
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.07
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.08
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.09
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.10
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.11
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2022.12
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2023.01
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2023.02
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2023.03
-
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2023.04
-
cpe:2.3:a:cisco:broadworks_application_server:2022.08
-
cpe:2.3:a:cisco:broadworks_application_server:2022.09
-
cpe:2.3:a:cisco:broadworks_application_server:2022.10
-
cpe:2.3:a:cisco:broadworks_application_server:2022.11
-
cpe:2.3:a:cisco:broadworks_application_server:2022.12
-
cpe:2.3:a:cisco:broadworks_application_server:2023.01
-
cpe:2.3:a:cisco:broadworks_application_server:2023.02
-
cpe:2.3:a:cisco:broadworks_application_server:2023.03
-
cpe:2.3:a:cisco:broadworks_application_server:2023.04
-
cpe:2.3:a:cisco:broadworks_application_server:23.0
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2018.12
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.01
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.02
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.03
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.04
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.05
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.06
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.07
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.08
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.09
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.10
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.11
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2019.12
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.01
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.02
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.03
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.04
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.05
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.06
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.07
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.08
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.09
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.10
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.11
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2020.12
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.01
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.02
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.03
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.04
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.05
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.06
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.07
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.08
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.09
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.10
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.11
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2021.12
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.01
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.02
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.03
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.04
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.05
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.06
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.07
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.08
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.09
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.10
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.11
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2022.12
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2023.01
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2023.02
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2023.03
-
cpe:2.3:a:cisco:broadworks_application_server:23.0.2023.04
-
cpe:2.3:a:cisco:broadworks_application_server:24.0
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2020.07
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2020.08
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2020.09
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2020.10
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2020.11
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2020.12
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.01
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.02
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.03
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.04
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.05
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.06
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.07
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.08
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.09
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.10
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.11
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2021.12
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.01
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.02
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.03
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.04
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.05
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.06
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.07
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.08
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.09
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.10
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.11
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2022.12
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2023.01
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2023.02
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2023.03
-
cpe:2.3:a:cisco:broadworks_application_server:24.0.2023.04
-
cpe:2.3:a:cisco:broadworks_database_server:-
-
cpe:2.3:a:cisco:broadworks_execution_server:-
-
cpe:2.3:a:cisco:broadworks_media_server:-
-
cpe:2.3:a:cisco:broadworks_network_database_server:-
-
cpe:2.3:a:cisco:broadworks_network_function_manager:-
-
cpe:2.3:a:cisco:broadworks_network_server:-
-
cpe:2.3:a:cisco:broadworks_profile_server:-
-
cpe:2.3:a:cisco:broadworks_service_control_function_server:-
-
cpe:2.3:a:cisco:broadworks_troubleshooting_server:-
-
cpe:2.3:a:cisco:broadworks_xtended_services_platform:-