Boletines de Vulnerabilidades

Cisco BroadWorks Application Delivery Platform and Xtended Services Platform Authentication Bypass Vulnerability


Información sobre el sistema

   
Software afectado Cisco

Descripción

A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This vulnerability is due to the method used to validate SSO tokens. An attacker could exploit this vulnerability by authenticating to the application with forged credentials. A successful exploit could allow the attacker to commit

More info:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-auth-bypass-kCggMWhX?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20BroadWorks%20Application%20Delivery%20Platform%20and%20Xtended%20Services%20Platform%20Authentication%20Bypass%20Vulnerability&vs_k=1

Identificadores estándar

Propiedad Valor
CVE CVE-2023-20238.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2023-09-07

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT