CVE-2023-20198: Cisco IOS XE Web UI Privilege Escalation Vulnerability

Published Oct 16, 2023
·
Updated

Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.

Other sources

Cisco is aware of active exploitation of a previously unknown vulnerability in the web UI feature of Cisco IOS XE Software when exposed to the internet or to untrusted networks. This vulnerability allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access. The attacker can then use that account to gain control of the affected system. For steps to close the attack vector for this vulnerability, see the Recommendations section of this advisory  Cisco will provide updates on the status of this investigation and when a software patch is available.

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

Affected Software

9 affected components
Cisco IOS XE Web UI
All of the following
rockwellautomation Allen-bradley Stratix 5200 Firmware<17.12.02
rockwellautomation Allen-bradley Stratix 5200
All of the following
rockwellautomation Allen-bradley Stratix 5800 Firmware<17.12.02
rockwellautomation Allen-bradley Stratix 5800
Cisco IOS XE>=16.12<16.12.10a
Cisco IOS XE>=17.3<17.3.8a
Cisco IOS XE>=17.6<17.6.6a
Cisco IOS XE>=17.9<17.9.4a

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Restrict access to Cisco IOS XE Web UI from the internet and from untrusted networks (e.g., block or filter access at the perimeter firewall or apply ACLs) as the advisory notes exploitation occurs when the Web UI is exposed to the internet or untrusted networks.

  2. Compensating control

    Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02.

  3. Operational

    For affected products, determine if a system may have been compromised per vendor instructions and immediately report positive findings to CISA.

Event History

Oct 16, 2023
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
DescriptionSeverityWeakness
Data Sourced
04:15 PM
DescriptionSeverity
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
News Published
via Dark Reading·08:44 PM
Jan 10, 2024
News Published
08:42 PM
Oct 12, 2024
News Published
via The Register·03:05 AM
News Published
via The Register·03:09 AM
Dec 3, 2024
News Published
via The Register·11:45 AM
Dec 20, 2024
News Published
via Dark Reading·12:00 AM
Feb 13, 2025
News Published
via The Register·06:34 PM
Feb 14, 2025
News Published
via BleepingComputer·12:56 PM
News Published
via BleepingComputer·12:58 PM
News Published
via Dark Reading·02:30 PM
Jun 23, 2025
News Published
via BleepingComputer·03:23 PM
Oct 31, 2025
News Published
via BleepingComputer·03:38 PM
Nov 2, 2025
News Published
via The Register·11:30 PM

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-20198?

CVE-2023-20198 refers to a privilege escalation vulnerability in Cisco IOS XE Web UI.

2

What is the severity of CVE-2023-20198?

The severity of CVE-2023-20198 is high.

3

How does CVE-2023-20198 impact Cisco IOS XE Web UI?

CVE-2023-20198 allows a remote, unauthenticated attacker to create an account with level 15 access and gain control of the affected device.

4

How can I fix CVE-2023-20198?

To fix CVE-2023-20198, apply the necessary security patches provided by Cisco.

5

Where can I find more information about CVE-2023-20198?

More information about CVE-2023-20198 can be found on the Cisco Security Advisory page: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203