CVE-2023-20216: Cisco Broadworks Application Delivery Platform

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions. There are workarounds that address this vulnerability.

Affected products

  • Cisco Broadworks Application Delivery Platform: before ri.2023.05 (fixed in ri.2023.05)
  • Cisco Broadworks Application Server: before 23.0.2023.05 (fixed in 23.0.2023.05); before 2023.05 (fixed in 2023.05); from 24.0, before 24.0.2023.05 (fixed in 24.0.2023.05)
  • Cisco Broadworks Database Server: before 2023.05 (fixed in 2023.05)
  • Cisco Broadworks Execution Server: before 2023.05 (fixed in 2023.05)
  • Cisco Broadworks Media Server: before 2023.05 (fixed in 2023.05)
  • Cisco Broadworks Network Database Server: before 2023.05 (fixed in 2023.05)
  • Cisco Broadworks Network Function Manager: before 2023.05 (fixed in 2023.05)
  • Cisco Broadworks Network Server: before 23.0.2023.05 (fixed in 23.0.2023.05); before 2023.05 (fixed in 2023.05)
  • Cisco Broadworks Profile Server: before 23.0.2023.05 (fixed in 23.0.2023.05); before 2023.05 (fixed in 2023.05)
  • Cisco Broadworks Service Control Function Server: before 2023.05 (fixed in 2023.05)
  • Cisco Broadworks Troubleshooting Server: before 2023.06 (fixed in 2023.06)
  • Cisco Broadworks Xtended Services Platform: before 23.0.2023.05 (fixed in 23.0.2023.05); before 2023.05 (fixed in 2023.05)

Published 2023-08-03. Last modified 2026-06-17.