← Vulnerability feed

Vulnerability record · CVE-2023-20273 · published 25 October 2023

CVE-2023-20273: Cisco IOS XE web UI command injection allows root command execution

Cisco · Ios Xe

Cisco IOS XE's web UI fails to properly validate input, letting an authenticated remote attacker inject operating system commands. Because the injected commands run as root, a valid web UI session is enough to take full control of the underlying device OS.

7.2 CVSS 3.1 High CISA KEV since 23 Oct 2023 EPSS 90% · top 0.2% CWE-78 · OS command injection
7.2CVSS 3.1 base score
90%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw yields root command execution on network infrastructure, is in CISA KEV, and has a very high EPSS probability, so it warrants immediate patching and compromise checks.

What it is

Cisco IOS XE's web UI fails to properly validate input, letting an authenticated remote attacker inject operating system commands. Because the injected commands run as root, a valid web UI session is enough to take full control of the underlying device OS.

Impact

An attacker with web UI access can execute arbitrary commands as root on the device, enabling configuration changes, credential access, persistence, and full compromise of the appliance.

Attack surface

Reached over the network through the IOS XE web UI; the CVSS vector shows PR:H, so the attacker needs high-level privileges (an authenticated web UI account) and no user interaction.

Exploitation

Listed in CISA KEV with a 30-day EPSS probability of 0.896 (99.8th percentile), indicating active exploitation in the wild; references are vendor advisory and US government resources only.

What to do

  • Apply the Cisco IOS XE software update from the vendor advisory as the primary fix.
  • Disable the HTTP/HTTPS web UI server on internet-facing and untrusted-network devices per Cisco guidance and BOD 23-02.
  • Restrict web UI management access to trusted management networks and remove unnecessary accounts.
  • After patching, follow Cisco instructions to check for compromise and report positive findings to CISA.
  • Audit web UI accounts and privileges, since exploitation requires an authenticated session.

Detection

  • Review IOS XE web UI and system logs for unexpected command execution or anomalous HTTP requests to the web UI.
  • Hunt for new or modified local accounts, configuration changes, and unexpected outbound connections from IOS XE devices.
  • Monitor for web UI access from untrusted networks or unusual source addresses.
  • Compare device configurations against known-good baselines to spot post-exploitation changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-20273 to the Known Exploited Vulnerabilities catalog on 23 October 2023 as "Cisco IOS XE Web UI Command Injection Vulnerability". Required action: Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA. Federal deadline 27 October 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20273 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed9.8CVE-2018-0151Cisco IOS/IOS XE QoS UDP Port 18999 Buffer OverflowCisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. …KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2023-20273), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.