Junglewise Threat Intelligence

CVE-2023-20198: Cisco IOS XE Web UI Privilege Escalation Vulnerability

CVE-2023-20198 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2023-10-16

Technologies: Cisco IOS XE. Vendors: Rockwell Automation, Cisco.

Executive brief

A privilege escalation vulnerability in the Cisco IOS XE Web UI allows a remote, unauthenticated attacker to create a local account with privilege level 15 access. This initial access can be leveraged to gain full control of the affected device. The vulnerability has been observed being exploited in the wild in conjunction with CVE-2023-20273 to install a persistent implant.

Affected products

  • Cisco IOS XE All versions with Web UI enabled
  • Rockwell Automation Allen-Bradley Stratix 5200 firmware versions up to (excluding) 17.12.02
  • Rockwell Automation Allen-Bradley Stratix 5800 firmware versions up to (excluding) 17.12.02

Timeline

  • 2023-10-16: disclosed: Initial disclosure and publication date
  • 2023-10-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-10-16: exploited: Observed active exploitation in the wild reported by Cisco

Related threats