CVE-2023-20020
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper input validation when parsing HTTP requests. An attacker could exploit this vulnerability by sending a sustained stream of crafted requests to an affected device. A successful exploit could allow the attacker to cause all subsequent requests to be dropped, resulting in a DoS condition.
Una vulnerabilidad en la aplicación Device Management Servlet application of Cisco BroadWorks Application Delivery Platform y Cisco BroadWorks Xtended Services Platform podría permitir que un atacante remoto no autenticado cause una condición de denegación de servicio (DoS) en un dispositivo afectado. Esta vulnerabilidad se debe a una validación de entrada incorrecta al analizar solicitudes HTTP. Un atacante podría aprovechar esta vulnerabilidad enviando un flujo sostenido de solicitudes manipuladas a un dispositivo afectado. Un exploit exitoso podría permitir al atacante provocar que se eliminen todas las solicitudes posteriores, lo que resultaría en una condición DoS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-27 CVE Reserved
- 2023-01-19 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Broadworks Application Delivery Platform Device Management Search vendor "Cisco" for product "Broadworks Application Delivery Platform Device Management" | >= 22.0 < 2022.11_1.273 Search vendor "Cisco" for product "Broadworks Application Delivery Platform Device Management" and version " >= 22.0 < 2022.11_1.273" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Broadworks Xtended Services Platform Search vendor "Cisco" for product "Broadworks Xtended Services Platform" | >= 22.0 < 23.0.1075.ap384245 Search vendor "Cisco" for product "Broadworks Xtended Services Platform" and version " >= 22.0 < 23.0.1075.ap384245" | - |
Affected
|