Exploited Vulnerabilities Daily
🌐 English

Home › Cisco

CVE-2023-20198: Cisco IOS XE Web UI

EPSS99.5%No. 183 of 1739 in KEV
CVE year2023listed the same year
Same vendor in KEV100
Same product1
FieldValue
VendorCisco
ProductIOS XE Web UI
NameCisco IOS XE Web UI Privilege Escalation Vulnerability
Added to KEV2023-10-16
US federal due date2023-10-20
Ransomware useUnknown
CWECWE-420

CISA description

Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.

NVD — CVE-2023-20198

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Cisco IOS XE Web UI vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-16.