CVE-2023-20273: Cisco Cisco IOS XE Web UI
EPSS89.6%No. 472 of 1739 in KEV
CVE year2023listed the same year
Same vendor in KEV100
Same product1
| Field | Value |
|---|---|
| Vendor | Cisco |
| Product | Cisco IOS XE Web UI |
| Name | Cisco IOS XE Web UI Command Injection Vulnerability |
| Added to KEV | 2023-10-23 |
| US federal due date | 2023-10-27 |
| Ransomware use | Unknown |
| CWE | CWE-78 |
CISA description
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Cisco Cisco IOS XE Web UI vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-23.