Cisco BroadWorks CVE-2023-20237: The SSO Bypass Scare
In September 2023 Cisco rushed out patches for CVE-2023-20237, a critical authentication bypass in BroadWorks' single-sign-on flows that could let attackers authenticate as any user. With evidence of active scanning, carrier admins ran an emergency patch marathon.
