PT-2023-6168 · Cisco · Cisco Ios Xe

Published

2023-10-16

·

Updated

2025-09-25

·

CVE-2023-20198

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XE (affected versions not specified)
Description The vulnerability in Cisco IOS XE allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access, effectively enabling a complete takeover of the system. This issue is actively being exploited in the wild, with tens of thousands of devices reportedly compromised. The vulnerability is related to the web UI feature of Cisco IOS XE Software when exposed to the internet or untrusted networks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the web UI feature on all internet-facing systems or untrusted networks to minimize the risk of exploitation. Restrict access to the web UI to only trusted networks and users. Monitor for malicious activity and report findings to the relevant authorities. Apply the recommended mitigations from Cisco, such as disabling the HTTP Server feature, to reduce the risk of exploitation.

Exploit

RCE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2023-06875
CVE-2023-20198

Affected Products

Cisco Ios Xe