Executive brief
A command injection vulnerability in the Cisco IOS XE Web UI allows an authenticated, remote attacker to execute commands with root privileges due to insufficient input validation. This vulnerability was actively exploited in the wild, often chained with CVE-2023-20198, to deploy a persistent implant on the file system.
Affected products
- Cisco IOS XE 16.1.1 and later
Timeline
- 2023-10-23: disclosed
- 2023-10-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog