CVE-2023-20198 Details
Description
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.
A privilege escalation vulnerability has been identified in the web user interface of Cisco IOS XE Software. This vulnerability allows a remote, unauthenticated attacker to create a local user account with privilege level 15. Once the account is established, the attacker can log in and, using the newly created account, escalate privileges to root and write an implant to the file system. The vulnerability is present in Cisco IOS XE Software versions 17.9, 17.6, and 17.3, as well as in the 16.12 release for Catalyst 3650 and 3850 switches. The web UI feature must be enabled for the vulnerability to be exploitable.
Cisco has released software updates that address this vulnerability. Affected users should upgrade to Cisco IOS XE Software releases 17.9.4a, 17.6.6a, or 17.3.8a. For Catalyst 3650 and 3850 switches, the fixed release is 16.12.10a. Instructions for downloading the updates are available on the Cisco Support and Downloads page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 23, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20198 | CISA-ADP | US Government Resource |
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z | CVE | MitigationVendor Advisory |
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z | [email protected] | MitigationVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Cisco IOS XE Web UI Privilege Escalation Vulnerability | Oct 16, 2023 | Oct 20, 2023 | Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-420 | Unprotected Alternate Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rockwellautomation allen-bradley stratix 5200 firmware | < 17.12.02 |
CPE
Remediation
| |
| rockwellautomation allen-bradley stratix 5200 | All versions |
CPE
Remediation
| |
| rockwellautomation allen-bradley stratix 5800 firmware | < 17.12.02 |
CPE
Remediation
| |
| rockwellautomation allen-bradley stratix 5800 | All versions |
CPE
Remediation
| |
| cisco ios xe | >= 16.12, < 16.12.10a >= 17.3, < 17.3.8a >= 17.6, < 17.6.6a >= 17.9, < 17.9.4a |
CPE
Remediation
| |
Change History
20 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 28, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| May 15, 2025 | Reanalysis | [email protected] |
| Apr 3, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 17, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 25, 2024 | CVE Modified | [email protected] |
| Nov 15, 2023 | Reanalysis | [email protected] |
| Nov 15, 2023 | Modified Analysis | [email protected] |
| Nov 14, 2023 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Oct 25, 2023 | CVE Modified | [email protected] |
| Oct 24, 2023 | Initial Analysis | [email protected] |
| Oct 16, 2023 | CVE Modified | [email protected] |
| Oct 16, 2023 | CVE Modified | [email protected] |