Lucene search

K
cisa_kevCISACISA-KEV-CVE-2023-20198
HistoryOct 16, 2023 - 12:00 a.m.

Cisco IOS XE Web UI Privilege Escalation Vulnerability

2023-10-1600:00:00
CISA
www.cisa.gov
124
cisco
ios xe
web ui
privilege escalation
vulnerability
remote
unauthenticated
attacker
account
level 15
access
device control

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.866

Percentile

98.7%

Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.866

Percentile

98.7%