Vulnerability record · CVE-2023-20273 · published 25 October 2023
CVE-2023-20273: Cisco IOS XE web UI command injection allows root command execution
Cisco · Ios Xe
Cisco IOS XE's web UI fails to properly validate input, letting an authenticated remote attacker inject operating system commands. Because the injected commands run as root, a valid web UI session is enough to take full control of the underlying device OS.
Description
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw yields root command execution on network infrastructure, is in CISA KEV, and has a very high EPSS probability, so it warrants immediate patching and compromise checks.
What it is
Cisco IOS XE's web UI fails to properly validate input, letting an authenticated remote attacker inject operating system commands. Because the injected commands run as root, a valid web UI session is enough to take full control of the underlying device OS.
Impact
An attacker with web UI access can execute arbitrary commands as root on the device, enabling configuration changes, credential access, persistence, and full compromise of the appliance.
Attack surface
Reached over the network through the IOS XE web UI; the CVSS vector shows PR:H, so the attacker needs high-level privileges (an authenticated web UI account) and no user interaction.
Exploitation
Listed in CISA KEV with a 30-day EPSS probability of 0.896 (99.8th percentile), indicating active exploitation in the wild; references are vendor advisory and US government resources only.
What to do
- Apply the Cisco IOS XE software update from the vendor advisory as the primary fix.
- Disable the HTTP/HTTPS web UI server on internet-facing and untrusted-network devices per Cisco guidance and BOD 23-02.
- Restrict web UI management access to trusted management networks and remove unnecessary accounts.
- After patching, follow Cisco instructions to check for compromise and report positive findings to CISA.
- Audit web UI accounts and privileges, since exploitation requires an authenticated session.
Detection
- Review IOS XE web UI and system logs for unexpected command execution or anomalous HTTP requests to the web UI.
- Hunt for new or modified local accounts, configuration changes, and unexpected outbound connections from IOS XE devices.
- Monitor for web UI access from untrusted networks or unusual source addresses.
- Compare device configurations against known-good baselines to spot post-exploitation changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-20273 to the Known Exploited Vulnerabilities catalog on 23 October 2023 as "Cisco IOS XE Web UI Command Injection Vulnerability". Required action: Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA. Federal deadline 27 October 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-20273 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-20273), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.