iTnews Asia
  • Home
  • News
  • Networking

Cisco SSO authentication bug patched

Cisco SSO authentication bug patched

BroadWorks platforms vulnerable.

By Richard Chirgwin on Sep 7, 2023 3:23PM

Cisco has announced patches for a critical credential forgery bug in some of its BroadWorks platforms.

The networking vendor said CVE-2023-20238 affects the single sign-on implementation used by its BroadWorks Xtended Services platform and BroadWorks application delivery platform.

The bug “could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system”, the advisory stated.

An attacker using a valid user ID to authenticate with forged credentials could commit toll fraud, the advisory said, or “execute commands at the privilege level of the forged account” – all the way up to administrator level.

At that level, “the attacker would have the ability to view confidential information, modify customer settings, or modify settings for other users.”

The two BroadWorks platforms are affected if they have any of the following applications enabled: AuthenticationService, BWCallCenter, BWReceptionist, CustomMediaFilesRetrieval, ModeratorClientApp, PublicECLQuery, PublicReporting, UCAPI, Xsi-Actions, Xsi-Events, Xsi-MMTel, or Xsi-VTR," Cisco said.

Users of BroadWorks Application Delivery and Xtended Services version 22 or below need to migrate to a fixed release; a patch is available for users on version 23 branches.

In a separate advisory, Cisco also announced a high-severity denial-of-service bug in its Identity Services Engine (ISE), CVE-2023-20243.

The ISE’s RADIUS message processor, present in a number of network access devices, can be crashed with a crafted packet.

Another four less severe bugs were patched in Cisco’s latest cycle.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
broadworks cisco networking security

Related Articles

  • Malicious AI agents can severely disrupt APAC enterprises
  • A data-first AI strategy is critical to managing security threats in 2026
  • Malicious AI inputs are creating a new and critical security threat
  • Beware the pitfalls of using a ‘DIY security’ approach
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

TD Tawandang ties up with Google Cloud to serve mom and pop shops

TD Tawandang ties up with Google Cloud to serve mom and pop shops

TIME dotCom to use cyber security mesh platform

TIME dotCom to use cyber security mesh platform

IMDA launches accelerator to help Poly and ITE students land tech jobs

IMDA launches accelerator to help Poly and ITE students land tech jobs

PPTEL to use Juniper equipment to upgrade network

PPTEL to use Juniper equipment to upgrade network

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.