CVE-2023-20198: Cisco IOS XE Web UI
EPSS99.5%No. 183 of 1739 in KEV
CVE year2023listed the same year
Same vendor in KEV100
Same product1
| Field | Value |
|---|---|
| Vendor | Cisco |
| Product | IOS XE Web UI |
| Name | Cisco IOS XE Web UI Privilege Escalation Vulnerability |
| Added to KEV | 2023-10-16 |
| US federal due date | 2023-10-20 |
| Ransomware use | Unknown |
| CWE | CWE-420 |
CISA description
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Cisco IOS XE Web UI vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-16.