> For the complete documentation index, see [llms.txt](https://eslam3kl.gitbook.io/blog/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://eslam3kl.gitbook.io/blog/web-application-findings/cve-2021-34786-cisco-broadworks-delete-admin-account.md).

# \[CVE-2021-34786] Cisco BroadWorks - Delete Admin Account

https\://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-broadworks-dJ9JT67N

Hello Everyone! Today I will talk about my last findings at Cisco products **BroadSoft BroadWorks**, one of Cisco's products.&#x20;

**CVE-2021-34786**: IDOR lead to delete arbitrary admin user accounts

<figure><img src="https://cdn-images-1.medium.com/max/800/1*-QfHKCEhP8jDCCOrwptTCw.png" alt=""><figcaption></figcaption></figure>

## **Content**

1. [BroadWorks structure](#broadworks-structure)
2. [Exploitation](#exploitation)
3. [Weakness points](#weakness-points)

### **BroadWorks structure**

At BroadWorks, we have an Admins group which have admins with write and read privileges and other admins with read-only privileges.

1. Read and Write: he can modify his data and other admins' data. Also, he can add users, change system preferences, delete users, and fully control the system
2. Read-only: he can modify his data and delete his account. He doesn’t have any other privileges “In my case”

I’ve got the second role (Read-only) and my task is trying to escalate my privileges to have Read and Write actions.

### **Exploitation**

Following up with the previous CVE for the same application, you can check it [here](https://eslam3kl.gitbook.io/blog/web-application-findings/cve-2021-34785-cisco-broadworks-privileged-escalation) for your reference. I've tried to delete my account and intercept the request.

<figure><img src="https://cdn-images-1.medium.com/max/800/1*cJSTk9YACVk-TyBrPcDofA.png" alt=""><figcaption></figcaption></figure>

We have the same required parameters `firstname/lastname/loginid` and the same exploit, just replace them with Admin account data and send the request.

What are the results? The admin account was deleted 😈

<figure><img src="https://cdn-images-1.medium.com/max/800/1*bbbh5mmHpIQBFfDYL_36MA.jpeg" alt=""><figcaption></figcaption></figure>

### **Weakness points**

1. At the change password function, it MUST ask me for the old password and if I forget it, it should ask me to contact the system administrator.
2. There’s no CSRF token attached with the user session to protect the system from performing the same attack using CSRF \[I have tried it and successed]
3. To delete an account, it MUST ask the user to enter his password or any security question

**Thanks for reading <3 Stay in touch**

[LinkedIn ](https://www.linkedin.com/in/eslam3kl/)| [GitHub](https://github.com/eslam3kl) | [Twitter](https://twitter.com/eslam3kll)
