Broadworks Application Server Cisco Broadworks Application Server

Do you want an email whenever new security vulnerabilities are reported in Cisco Broadworks Application Server?

Recent Cisco Broadworks Application Server Security Advisories

Advisory Title Published
2021-07-07 Cisco BroadWorks Application Server Information Disclosure Vulnerability July 7, 2021

By the Year

In 2024 there have been 0 vulnerabilities in Cisco Broadworks Application Server . Last year Broadworks Application Server had 3 security vulnerabilities published. Right now, Broadworks Application Server is on track to have less security vulnerabilities in 2024 than it did last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 3 6.43
2022 0 0.00
2021 1 4.30
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Broadworks Application Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Cisco Broadworks Application Server Security Vulnerabilities

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could

CVE-2023-20204 5.4 - Medium - August 03, 2023

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

XSS

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could

CVE-2023-20216 7.8 - High - August 03, 2023

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions. There are workarounds that address this vulnerability.

Incorrect Permission Assignment for Critical Resource

A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisco BroadWorks Xtended Services Platform could

CVE-2023-20019 6.1 - Medium - January 20, 2023

A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

XSS

A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could

CVE-2021-1562 4.3 - Medium - July 08, 2021

A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could allow an authenticated, remote attacker to access sensitive information on an affected system. This vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the XSI-Actions interface. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a specific set of commands. A successful exploit could allow the attacker to join a Call Center instance and have calls that they do not have permissions to access distributed to them from the Call Center queue. At the time of publication, Cisco had not released updates that address this vulnerability for Cisco BroadWorks Application Server. However, firmware patches are available.

Improper Input Validation

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Cisco Broadworks Application Server or by Cisco? Click the Watch button to subscribe.

Cisco
Vendor

subscribe