Vulnerability Bulletins

Cisco BroadWorks Application Delivery Platform and Xtended Services Platform Authentication Bypass Vulnerability


System information

   
Affected software Cisco

Description

A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This vulnerability is due to the method used to validate SSO tokens. An attacker could exploit this vulnerability by authenticating to the application with forged credentials. A successful exploit could allow the attacker to commit

More info:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-auth-bypass-kCggMWhX?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20BroadWorks%20Application%20Delivery%20Platform%20and%20Xtended%20Services%20Platform%20Authentication%20Bypass%20Vulnerability&vs_k=1

Standar resources

Property Value
CVE CVE-2023-20238.

Version history

Version Comments Date
1.0 Advisory issued 2023-09-07
Ministerio de Defensa
CNI
CCN
CCN-CERT