← Vulnerability feed

Vulnerability record · CVE-2023-20216 · published 3 August 2023

CVE-2023-20216: Cisco broadworks application delivery platform improper privilege management vulnerability

Cisco · Broadworks Application Delivery Platform

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions. There are workarounds that address this vulnerability.

7.8 CVSS 3.1 High EPSS 0.16% · top 95.8% CWE-269 · Improper privilege managementCWE-732 · Incorrect permission assignment
7.8CVSS 3.1 base score
0.16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability by authenticating to the application as a user with the BWORKS or BWSUPERADMIN role and issuing crafted commands on an affected system. A successful exploit could allow the attacker to execute commands beyond the sphere of their intended access level, including initiating installs or running operating system commands with elevated permissions. There are workarounds that address this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20216 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-20238Cisco broadworks application delivery platform improper authentication vulnerabilityA vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Pl…EPSS 16%6.1CVE-2023-20019Cisco broadworks application delivery platform cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cis…EPSS 0.59%5.4CVE-2024-20270Cisco broadworks xtended services platform cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platfor…EPSS 0.36%5.4CVE-2023-20204Cisco broadworks application delivery platform cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacke…EPSS 0.45%4.8CVE-2025-20307Cisco broadworks application delivery platform cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacke…EPSS 0.24%4.3CVE-2021-1562Cisco broadworks application server information exposure vulnerabilityA vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could allow an authenticated, remote attacker to access sensitive…EPSS 0.87%9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed

Source: NIST National Vulnerability Database (record CVE-2023-20216), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.