Cisco Addresses Critical Credential Forgery Bug in BroadWorks Platforms

Networking giant Cisco has issued patches for a critical vulnerability that could enable credential forgery in its BroadWorks platforms, potentially leading to toll fraud and unauthorized system access.

Cisco, a leading networking vendor, has responded swiftly to a critical security flaw affecting its BroadWorks Xtended Services platform and BroadWorks application delivery platform. This vulnerability, known as CVE-2023-20238, pertains to the platforms’ single sign-on (SSO) implementation.

The security advisory warns that this bug could be exploited by an unauthenticated attacker, allowing them to forge the necessary credentials to access the affected system. In practical terms, this means an attacker, armed with forged credentials obtained from a valid user ID, could engage in toll fraud or execute commands at the privilege level corresponding to the falsified account. This privilege level could extend to administrator access.

At the administrator level, the attacker would have the capability to perform a range of malicious actions, including viewing confidential information, modifying customer settings, or altering settings for other users.

Cisco also disclosed a high-severity denial-of-service vulnerability

This vulnerability affects the BroadWorks Xtended Services platform and BroadWorks application delivery platform if they have any of the following applications enabled: AuthenticationService, BWCallCenter, BWReceptionist, CustomMediaFilesRetrieval, ModeratorClientApp, PublicECLQuery, PublicReporting, UCAPI, Xsi-Actions, Xsi-Events, Xsi-MMTel, or Xsi-VTR.

Cisco has recommended that users of BroadWorks Application Delivery and Xtended Services versions 22 or lower migrate to a fixed release. For those on version 23 branches, a patch is available.

In a separate security advisory, Cisco also disclosed a high-severity denial-of-service vulnerability (CVE-2023-20243) in its Identity Services Engine (ISE). This flaw affects the ISE’s RADIUS message processor, which is found in various network access devices. Attackers can crash this component with a carefully crafted packet, causing a denial-of-service condition.

The company has diligently addressed these security issues in its latest cycle, underscoring its commitment to maintaining the integrity and security of its products.

Bibi Zuhra
Bibi Zuhra
Bibi Zuhra has a Master's degree in public administration and a Certificate in Entrepreneurship from Santa Rosa Junior college (California). Bibi has worked in research & marketing, and in policymaking, and also has more than four years of experience as an SEO Content Writer, and news articles for e-commerce, tourism, business, education, and lifestyle. she believe words have the power to change the world, and she try to do that through her work.

Similar Articles

Comments

Most Popular