Vulnerability record · CVE-2023-20198 · published 16 October 2023
CVE-2023-20198: Cisco IOS XE Web UI unauthenticated privilege escalation and implant deployment
Rockwellautomation · Allen Bradley Stratix 5200 Firmware
CVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local privilege 15 user. Cisco states the actors chained it with CVE-2023-20273 to escalate to root and write an implant to the file system, making it a full device compromise rather than a simple access bug.
Description
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable access with CVSS 10.0, confirmed in-the-wild exploitation, KEV listing and near-maximum EPSS make this an urgent patch-or-mitigate case.
What it is
CVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local privilege 15 user. Cisco states the actors chained it with CVE-2023-20273 to escalate to root and write an implant to the file system, making it a full device compromise rather than a simple access bug.
Impact
An attacker obtains privileged access to the device and, by chaining the second flaw, root-level control allowing implant installation and persistent control of the affected system.
Attack surface
Reachable over the network through the IOS XE web UI feature; the CVSS vector shows no privileges and no user interaction required. Exposure is limited to devices with the HTTP/HTTPS web UI enabled and reachable from untrusted networks.
Exploitation
Cisco describes observed exploitation in the wild, CISA added it to KEV on 2023-10-16 with a 2023-10-20 due date, and EPSS is 0.99571 (99.9th percentile). No ransomware campaign use is recorded.
What to do
- Apply the fixed IOS XE releases listed in Cisco's advisory (CSCwh87343) as the first action.
- If patching cannot be done immediately, disable the HTTP/HTTPS web UI server on internet-facing and untrusted-network devices per Cisco guidance.
- Restrict management access to the web UI with ACLs and place it behind a management network, consistent with BOD 23-02.
- Check devices for unauthorized local users and for implant artifacts, and report positive findings to CISA as the KEV entry directs.
- Re-check the advisory for updated fixed-release lists and the Software Checker before declaring remediation complete.
Detection
- Audit local user accounts on IOS XE devices for unexpected privilege 15 accounts and alert on their creation.
- Monitor web UI and management-plane logs for anomalous HTTP/HTTPS requests and authentication events from untrusted sources.
- Inspect the file system for unexpected files or implant artifacts written after suspicious web UI activity.
- Hunt for the CVE-2023-20273 follow-on behavior: privilege escalation from a newly created local user to root.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-20198 to the Known Exploited Vulnerabilities catalog on 16 October 2023 as "Cisco IOS XE Web UI Privilege Escalation Vulnerability". Required action: Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA. Federal deadline 20 October 2023.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z | MitigationVendor Advisory |
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20198 | US Government Resource |
Track CVE-2023-20198 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-20198), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.