LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-20198: Cisco IOS XE Web UI Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 16, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 20, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-20198 to its Known Exploited Vulnerabilities catalog on Oct 16, 2023, with a federal patch deadline of Oct 20, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The…

CVE-2023-20198 is a privilege escalation vulnerability in the web user interface of Cisco IOS XE. A remote, unauthenticated attacker can create an account with privilege level 15 access and then use that account to take control of the affected device. Because the Web UI is often left enabled on network infrastructure that sits at the edge of enterprise and service-provider environments, successful exploitation can give an attacker full administrative control over critical routing and switching gear.

This matters for any organization running Cisco IOS XE devices whose Web UI is reachable from untrusted networks. CISA has directed that exposed instances be verified for compliance with BOD 23-02, that vendor mitigations be applied, and that any evidence of compromise be reported immediately.

How it works

The underlying weakness is classified as CWE-420 (Unprotected Alternate Channel). In this case the alternate channel is the HTTP/HTTPS Web UI that Cisco IOS XE presents for device management. The flaw allows an unauthenticated remote party to create a new local user account that is granted the highest privilege level (15). Once that account exists, the attacker can authenticate through the normal management interfaces and reconfigure the device, install persistent access, or pivot deeper into the network.

Exact request sequences and any required conditions are not described here; defenders must consult the official Cisco advisory for the precise technical details of the attack surface and the conditions under which the vulnerability can be triggered.

Am I affected? How to find it in your systems

Cisco IOS XE is the operating system used on a wide range of Cisco routers, switches, and wireless controllers. The vulnerable component is the Web UI feature, which may be enabled by default or by configuration on many of these platforms.

Any device whose Web UI is exposed to the internet or to untrusted networks should be treated as high priority for both patching and compromise assessment.

How to remediate

The primary remediation is to apply the software update or configuration guidance published by Cisco for CVE-2023-20198. Confirm the exact fixed releases and any required interim work-arounds directly from the vendor advisory before deploying them in production.

CISA also requires that organizations verify compliance with BOD 23-02 for any internet-facing or untrusted-network-facing instances and report confirmed compromises.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with the following compensating controls:

These steps do not eliminate the vulnerability; they only shrink the attack surface until the official fix can be applied.

If your data may have been exposed

Actively exploited infrastructure vulnerabilities frequently lead to broader network compromise and data exposure. If your Cisco IOS XE devices were reachable and unpatched, treat them as potentially compromised: follow the vendor’s published indicators of compromise, collect forensic images if warranted, and report confirmed incidents to CISA as required. Separately, you can run a free exposure scan of your email addresses against known breach data sets to determine whether credentials or personal information associated with your organization have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS XE Web UI
WeaknessCWE-420
Added to CISA KEVOct 16, 2023
Federal patch deadlineOct 20, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities