SSO Vulnerability in Cisco BroadWorks Platforms
CVE-2023-20238
Summary
A vulnerability exists in the single sign-on (SSO) configuration of Cisco's BroadWorks platforms, allowing unauthenticated remote attackers to forge credentials necessary for system access. The flaw resides in the validation method for SSO tokens. By exploiting this issue, attackers can authenticate to applications using forged credentials, potentially leading to unauthorized actions. If an administrator's account is compromised, attackers could access sensitive data, modify customer settings, or alter configurations for other users. To execute such an attack, the perpetrator must possess a valid user ID associated with the vulnerable Cisco BroadWorks system.
Affected Version(s)
Cisco BroadWorks 23.0
Cisco BroadWorks 23.0 ap383785
Cisco BroadWorks 23.0 ap382487
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved