← Vulnerability feed

Vulnerability record · CVE-2023-20020 · published 20 January 2023

CVE-2023-20020: Cisco broadworks application delivery platform device management improper input validation vulnerability

Cisco · Broadworks Application Delivery Platform Device Management

A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when parsing HTTP requests. An attacker could exploit this vulnerability by sending a sustained stream of crafted requests to an affected device. A successful exploit could allow the attacker to cause all subsequent requests to be dropped, resulting in a DoS condition.

8.6 CVSS 3.1 High EPSS 0.86% · top 43.1% CWE-835 · CWE-835CWE-20 · Improper input validation
8.6CVSS 3.1 base score
0.86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation when parsing HTTP requests. An attacker could exploit this vulnerability by sending a sustained stream of crafted requests to an affected device. A successful exploit could allow the attacker to cause all subsequent requests to be dropped, resulting in a DoS condition.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20020 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-20238Cisco broadworks application delivery platform improper authentication vulnerabilityA vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Pl…EPSS 16%7.8CVE-2023-20216Cisco broadworks application delivery platform improper privilege management vulnerabilityA vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevat…EPSS 0.16%6.1CVE-2023-20019Cisco broadworks application delivery platform cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cis…EPSS 0.59%5.4CVE-2024-20270Cisco broadworks xtended services platform cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platfor…EPSS 0.36%5.4CVE-2023-20204Cisco broadworks application delivery platform cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacke…EPSS 0.45%8.6CVE-2024-20353Cisco ASA and FTD web server HTTP header parsing DoSCisco ASA and FTD management and VPN web servers fail to fully check errors when parsing an HTTP header, so a crafted request can crash and reload th…KEVEPSS 71%analysed

Source: NIST National Vulnerability Database (record CVE-2023-20020), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.