Broadworks Cisco Broadworks

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Cisco Broadworks.

Recent Cisco Broadworks Security Advisories

Advisory Title Published
2025-07-02 Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability July 2, 2025
2025-03-05 Cisco Webex for BroadWorks Credential Exposure Vulnerability March 5, 2025
2025-02-20 Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability February 20, 2025
2025-01-23 Cisco BroadWorks SIP Denial of Service Vulnerability January 23, 2025
2024-01-10 Cisco BroadWorks Application Delivery Platform and Xtended Services Platform Stored Cross-Site Scripting Vulnerability January 10, 2024
2023-09-06 Cisco BroadWorks Application Delivery Platform and Xtended Services Platform Authentication Bypass Vulnerability September 6, 2023
2023-08-02 Cisco BroadWorks CommPilot Application Software Cross-Site Scripting Vulnerability August 2, 2023
2023-07-20 Cisco BroadWorks Privilege Escalation Vulnerability July 20, 2023
2023-07-05 Cisco BroadWorks Privilege Escalation Vulnerability July 5, 2023
2023-04-19 Cisco BroadWorks Network Server TCP Denial of Service Vulnerability April 19, 2023

By the Year

In 2026 there have been 0 vulnerabilities in Cisco Broadworks. Last year, in 2025 Broadworks had 1 security vulnerability published. Right now, Broadworks is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 1 4.80
2024 0 0.00
2023 4 8.10
2022 1 6.10
2021 3 6.57

It may take a day or so for new Broadworks vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Cisco Broadworks Security Vulnerabilities

Cisco BroadWorks App Delivery Platform: Authenticated XSS via Web UI
CVE-2025-20307 4.8 - Medium - July 02, 2025

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.

XSS

Cisco BroadWorks SSO Auth Bypass Allows RCE via Forged Tokens
CVE-2023-20238 10 - Critical - September 06, 2023

A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This vulnerability is due to the method used to validate SSO tokens. An attacker could exploit this vulnerability by authenticating to the application with forged credentials. A successful exploit could allow the attacker to commit toll fraud or to execute commands at the privilege level of the forged account. If that account is an Administrator account, the attacker would have the ability to view confidential information, modify customer settings, or modify settings for other users. To exploit this vulnerability, the attacker would need a valid user ID that is associated with an affected Cisco BroadWorks system.

authentification

CVE-2023-20216: Privilege Escalation in Cisco BroadWorks Servers
CVE-2023-20216 7.8 - High - August 03, 2023

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions. There are workarounds that address this vulnerability.

Incorrect Permission Assignment for Critical Resource

Cisco BroadWorks CLI Privilege Escalation via Input Validation (CVE-2023-20210)
CVE-2023-20210 6 - Medium - July 12, 2023

A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected system. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, an attacker must have valid BroadWorks administrative privileges on the affected device.

Unauthenticated DoS via HTTP input validation in Cisco BroadWorks DM Servlet
CVE-2023-20020 8.6 - High - January 20, 2023

A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when parsing HTTP requests. An attacker could exploit this vulnerability by sending a sustained stream of crafted requests to an affected device. A successful exploit could allow the attacker to cause all subsequent requests to be dropped, resulting in a DoS condition.

Improper Input Validation

CVE-2022-20869: XSS via Web UI in Cisco BroadWorks App Delivery Platform
CVE-2022-20869 6.1 - Medium - August 10, 2022

A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

XSS

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2
CVE-2021-44228 10 - Critical - December 10, 2021

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Marshaling, Unmarshaling

A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could
CVE-2021-1562 4.3 - Medium - July 08, 2021

A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could allow an authenticated, remote attacker to access sensitive information on an affected system. This vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the XSI-Actions interface. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a specific set of commands. A successful exploit could allow the attacker to join a Call Center instance and have calls that they do not have permissions to access distributed to them from the Call Center queue. At the time of publication, Cisco had not released updates that address this vulnerability for Cisco BroadWorks Application Server. However, firmware patches are available.

Information Disclosure

A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could
CVE-2021-1530 5.4 - Medium - May 06, 2021

A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS) condition on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by uploading a crafted XML file that contains references to external entities. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a partial DoS condition on an affected system. There are workarounds that address this vulnerability.

XXE

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Cisco Broadworks or by Cisco? Click the Watch button to subscribe.

Cisco
Vendor

subscribe