Threats Tagged 'cve-2023-20238'
View all threats tagged with 'cve-2023-20238'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2023-20238'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2023-20238 is a critical vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Xtended Services Platform. It allows an unauthenticated remote attacker to forge SSO tokens and gain unauthorized access to affected systems. Exploitation requires knowledge of a valid user ID but no authentication or user interaction is needed. Successful exploitation can lead to toll fraud, command execution with the privileges of the forged account, and if an administrator account is forged, full control over confidential data and system settings. The vulnerability affects multiple versions of Cisco BroadWorks, including versions 21.sp1 through 23.0 with numerous patches. The CVSS score is 10.0, indicating critical severity with network attack vector, low complexity, no privileges required, and no user interaction. There are no known exploits in the wild yet. Join the discussion | CVE Database V5 | 09/06/2023, 17:08:28 UTC Added: 12/16/2025, 17:18:46 UTC |
Showing 1 to 1 of 1 result