Cisco Broadworks
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Cisco Broadworks.
Recent Cisco Broadworks Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2025-07-02 | Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability | July 2, 2025 |
| 2025-03-05 | Cisco Webex for BroadWorks Credential Exposure Vulnerability | March 5, 2025 |
| 2025-02-20 | Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability | February 20, 2025 |
| 2025-01-23 | Cisco BroadWorks SIP Denial of Service Vulnerability | January 23, 2025 |
| 2024-01-10 | Cisco BroadWorks Application Delivery Platform and Xtended Services Platform Stored Cross-Site Scripting Vulnerability | January 10, 2024 |
| 2023-09-06 | Cisco BroadWorks Application Delivery Platform and Xtended Services Platform Authentication Bypass Vulnerability | September 6, 2023 |
| 2023-08-02 | Cisco BroadWorks CommPilot Application Software Cross-Site Scripting Vulnerability | August 2, 2023 |
| 2023-07-20 | Cisco BroadWorks Privilege Escalation Vulnerability | July 20, 2023 |
| 2023-07-05 | Cisco BroadWorks Privilege Escalation Vulnerability | July 5, 2023 |
| 2023-04-19 | Cisco BroadWorks Network Server TCP Denial of Service Vulnerability | April 19, 2023 |
By the Year
In 2026 there have been 0 vulnerabilities in Cisco Broadworks. Last year, in 2025 Broadworks had 1 security vulnerability published. Right now, Broadworks is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 1 | 4.80 |
| 2024 | 0 | 0.00 |
| 2023 | 4 | 8.10 |
| 2022 | 1 | 6.10 |
| 2021 | 3 | 6.57 |
It may take a day or so for new Broadworks vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Cisco Broadworks Security Vulnerabilities
Cisco BroadWorks App Delivery Platform: Authenticated XSS via Web UI
CVE-2025-20307
4.8 - Medium
- July 02, 2025
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.
XSS
Cisco BroadWorks SSO Auth Bypass Allows RCE via Forged Tokens
CVE-2023-20238
10 - Critical
- September 06, 2023
A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This vulnerability is due to the method used to validate SSO tokens. An attacker could exploit this vulnerability by authenticating to the application with forged credentials. A successful exploit could allow the attacker to commit toll fraud or to execute commands at the privilege level of the forged account. If that account is an Administrator account, the attacker would have the ability to view confidential information, modify customer settings, or modify settings for other users. To exploit this vulnerability, the attacker would need a valid user ID that is associated with an affected Cisco BroadWorks system.
authentification
CVE-2023-20216: Privilege Escalation in Cisco BroadWorks Servers
CVE-2023-20216
7.8 - High
- August 03, 2023
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions. There are workarounds that address this vulnerability.
Incorrect Permission Assignment for Critical Resource
Cisco BroadWorks CLI Privilege Escalation via Input Validation (CVE-2023-20210)
CVE-2023-20210
6 - Medium
- July 12, 2023
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.
Unauthenticated DoS via HTTP input validation in Cisco BroadWorks DM Servlet
CVE-2023-20020
8.6 - High
- January 20, 2023
A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when parsing HTTP requests. An attacker could exploit this vulnerability by sending a sustained stream of crafted requests to an affected device. A successful exploit could allow the attacker to cause all subsequent requests to be dropped, resulting in a DoS condition.
Improper Input Validation
CVE-2022-20869: XSS via Web UI in Cisco BroadWorks App Delivery Platform
CVE-2022-20869
6.1 - Medium
- August 10, 2022
A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
XSS
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2
CVE-2021-44228
10 - Critical
- December 10, 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Marshaling, Unmarshaling
A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could
CVE-2021-1562
4.3 - Medium
- July 08, 2021
A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could allow an authenticated, remote attacker to access sensitive information on an affected system. This vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the XSI-Actions interface. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a specific set of commands. A successful exploit could allow the attacker to join a Call Center instance and have calls that they do not have permissions to access distributed to them from the Call Center queue. At the time of publication, Cisco had not released updates that address this vulnerability for Cisco BroadWorks Application Server. However, firmware patches are available.
Information Disclosure
A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could
CVE-2021-1530
5.4 - Medium
- May 06, 2021
A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS) condition on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by uploading a crafted XML file that contains references to external entities. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a partial DoS condition on an affected system. There are workarounds that address this vulnerability.
XXE
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Cisco Broadworks or by Cisco? Click the Watch button to subscribe.