← Vulnerability feed

Vulnerability record · CVE-2023-20198 · published 16 October 2023

CVE-2023-20198: Cisco IOS XE Web UI unauthenticated privilege escalation and implant deployment

Rockwellautomation · Allen Bradley Stratix 5200 Firmware

CVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local privilege 15 user. Cisco states the actors chained it with CVE-2023-20273 to escalate to root and write an implant to the file system, making it a full device compromise rather than a simple access bug.

10.0 CVSS 3.1 Critical CISA KEV since 16 Oct 2023 EPSS 100% · top 0.1% CWE-420 · CWE-420
10.0CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable access with CVSS 10.0, confirmed in-the-wild exploitation, KEV listing and near-maximum EPSS make this an urgent patch-or-mitigate case.

What it is

CVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local privilege 15 user. Cisco states the actors chained it with CVE-2023-20273 to escalate to root and write an implant to the file system, making it a full device compromise rather than a simple access bug.

Impact

An attacker obtains privileged access to the device and, by chaining the second flaw, root-level control allowing implant installation and persistent control of the affected system.

Attack surface

Reachable over the network through the IOS XE web UI feature; the CVSS vector shows no privileges and no user interaction required. Exposure is limited to devices with the HTTP/HTTPS web UI enabled and reachable from untrusted networks.

Exploitation

Cisco describes observed exploitation in the wild, CISA added it to KEV on 2023-10-16 with a 2023-10-20 due date, and EPSS is 0.99571 (99.9th percentile). No ransomware campaign use is recorded.

What to do

  • Apply the fixed IOS XE releases listed in Cisco's advisory (CSCwh87343) as the first action.
  • If patching cannot be done immediately, disable the HTTP/HTTPS web UI server on internet-facing and untrusted-network devices per Cisco guidance.
  • Restrict management access to the web UI with ACLs and place it behind a management network, consistent with BOD 23-02.
  • Check devices for unauthorized local users and for implant artifacts, and report positive findings to CISA as the KEV entry directs.
  • Re-check the advisory for updated fixed-release lists and the Software Checker before declaring remediation complete.

Detection

  • Audit local user accounts on IOS XE devices for unexpected privilege 15 accounts and alert on their creation.
  • Monitor web UI and management-plane logs for anomalous HTTP/HTTPS requests and authentication events from untrusted sources.
  • Inspect the file system for unexpected files or implant artifacts written after suspicious web UI activity.
  • Hunt for the CVE-2023-20273 follow-on behavior: privilege escalation from a newly created local user to root.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-20198 to the Known Exploited Vulnerabilities catalog on 16 October 2023 as "Cisco IOS XE Web UI Privilege Escalation Vulnerability". Required action: Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA. Federal deadline 20 October 2023.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20198 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0151Cisco IOS/IOS XE QoS UDP Port 18999 Buffer OverflowCisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. …KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed8.8CVE-2017-6740Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP subsystem affecting SNMP versions 1, 2c, and 3. An authenticated remote attacker can send …KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2023-20198), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.