Junglewise Threat Intelligence

CVE-2023-20273: Cisco IOS XE Web UI Command Injection Vulnerability

CVE-2023-20273 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2023-10-23

Technologies: Cisco IOS XE. Vendors: Cisco.

Executive brief

A command injection vulnerability in the Cisco IOS XE Web UI allows an authenticated, remote attacker to execute commands with root privileges due to insufficient input validation. This vulnerability was actively exploited in the wild, often chained with CVE-2023-20198, to deploy a persistent implant on the file system.

Affected products

  • Cisco IOS XE 16.1.1 and later

Timeline

  • 2023-10-23: disclosed
  • 2023-10-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats