SB2023090721 - Improper Authentication in Cisco BroadWorks Application Delivery Platform and Xtended Services Platform
Published: September 7, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2023-20238)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the method used to validate SSO tokens. A remote attacker can forge the credentials required to access an affected system.
Remediation
Install update from vendor's website.