PT-2023-6168 · Cisco · Cisco Ios Xe
Published
2023-10-16
·
Updated
2025-08-28
·
CVE-2023-20198
10
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Cisco IOS XE versions prior to the fixed version
Description:
The vulnerability in Cisco IOS XE allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access. This vulnerability is actively being exploited in the wild, with over 40,000 devices reportedly compromised. The vulnerability affects devices that have the Web User Interface (Web UI) feature enabled.
Recommendations:
To resolve the issue, update Cisco IOS XE to a version that includes the fix for this vulnerability. If an update is not available, disable the HTTP Server feature on all internet-facing systems to mitigate the risk of exploitation. Additionally, restrict access to the Web UI feature to minimize the risk of exploitation.
Note: The exact fixed version is not specified in the provided input, so it is recommended to check the official Cisco website for the latest information on this vulnerability and its fix.
Exploit
Fix
RCE
Improper Privilege Management
Related Identifiers
Affected Products
References · 510
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/cisco_ios_xe_cli_exec_cve_2023_20198.rb⭐ 34266 🔗 14003 · Exploit
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/cisco_ios_xe_os_exec_cve_2023_20273.rb⭐ 34266 🔗 14003 · Exploit
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/misc/cisco_ios_xe_rce.rb⭐ 34266 🔗 14003 · Exploit
- 🔥 https://github.com/smokeintheshell/CVE-2023-20198⭐ 40 🔗 7 · Exploit
- 🔥 https://github.com/W01fh4cker/CVE-2023-20198-RCE⭐ 37 🔗 10 · Exploit
- 🔥 https://github.com/fox-it/cisco-ios-xe-implant-detection⭐ 36 🔗 8 · Exploit
- 🔥 https://github.com/ZephrFish/Cisco-IOS-XE-Scanner⭐ 31 🔗 11 · Exploit
- 🔥 https://github.com/ZephrFish/CVE-2023-20198-Checker⭐ 31 🔗 11 · Exploit
- 🔥 https://github.com/Shadow0ps/CVE-2023-20198-Scanner⭐ 30 🔗 6 · Exploit
- 🔥 https://github.com/Atea-Redteam/CVE-2023-20198⭐ 17 🔗 14 · Exploit
- 🔥 https://github.com/Tounsi007/CVE-2023-20198⭐ 9 🔗 6 · Exploit
- 🔥 https://github.com/Pushkarup/CVE-2023-20198⭐ 8 🔗 7 · Exploit
- 🔥 https://github.com/cert-orangecyberdefense/Cisco_CVE-2023-20198⭐ 9 🔗 3 · Exploit
- 🔥 https://github.com/RevoltSecurities/CVE-2023-20198⭐ 6 🔗 3 · Exploit
- 🔥 https://github.com/iveresk/cve-2023-20198⭐ 4 🔗 4 · Exploit