CVE-2023-20273: Cisco IOS XE Web UI Command Injection Vulnerability
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
Other sources
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Verify that Cisco IOS XE Web UI instances exposed to the internet or to untrusted networks are in compliance with BOD 23-02. Implement the mitigations and access restrictions required by BOD 23-02 for those instances to reduce exposure.
- Operational
For affected Cisco IOS XE Web UI products exposed to the internet or to untrusted networks, follow vendor instructions to determine if a system may have been compromised and immediately report any positive findings to CISA.
- Operational
Investigate whether the system has been chained with CVE-2023-20198 (look for creation of a new local user) and check the filesystem for any implant or files written with elevated/root privileges as described in vendor guidance.
Event History
Frequently Asked Questions
What is CVE-2023-20273?
CVE-2023-20273 is a command injection vulnerability in the Cisco IOS XE web user interface.
How does CVE-2023-20273 work?
CVE-2023-20273 allows an attacker to execute arbitrary commands on the affected system through the web user interface.
Is there a specific software affected by CVE-2023-20273?
Yes, the Cisco IOS XE web user interface is affected by CVE-2023-20273.
How severe is CVE-2023-20273?
CVE-2023-20273 has a severity rating of high.
Is there a fix available for CVE-2023-20273?
Yes, Cisco has released a security advisory with instructions on how to mitigate the vulnerability.