Lucene search

K
cvelistCiscoCVELIST:CVE-2023-20198
HistoryOct 16, 2023 - 3:12 p.m.

CVE-2023-20198

2023-10-1615:12:58
cisco
www.cve.org
1
cisco
ios xe software
web ui
exploitation
cve-2023-20198
cve-2023-20273
cvss score 10.0
cvss score 7.2
cscwh87343

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

8.7 High

AI Score

Confidence

High

0.853 High

EPSS

Percentile

98.6%

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

CNA Affected

[
  {
    "vendor": "Cisco",
    "product": "Cisco IOS XE Software",
    "versions": [
      {
        "version": "16.1.1",
        "status": "affected"
      },
      {
        "version": "16.1.2",
        "status": "affected"
      },
      {
        "version": "16.1.3",
        "status": "affected"
      },
      {
        "version": "16.2.1",
        "status": "affected"
      },
      {
        "version": "16.2.2",
        "status": "affected"
      },
      {
        "version": "16.3.1",
        "status": "affected"
      },
      {
        "version": "16.3.2",
        "status": "affected"
      },
      {
        "version": "16.3.3",
        "status": "affected"
      },
      {
        "version": "16.3.1a",
        "status": "affected"
      },
      {
        "version": "16.3.4",
        "status": "affected"
      },
      {
        "version": "16.3.5",
        "status": "affected"
      },
      {
        "version": "16.3.5b",
        "status": "affected"
      },
      {
        "version": "16.3.6",
        "status": "affected"
      },
      {
        "version": "16.3.7",
        "status": "affected"
      },
      {
        "version": "16.3.8",
        "status": "affected"
      },
      {
        "version": "16.3.9",
        "status": "affected"
      },
      {
        "version": "16.3.10",
        "status": "affected"
      },
      {
        "version": "16.3.11",
        "status": "affected"
      },
      {
        "version": "16.4.1",
        "status": "affected"
      },
      {
        "version": "16.4.2",
        "status": "affected"
      },
      {
        "version": "16.4.3",
        "status": "affected"
      },
      {
        "version": "16.5.1",
        "status": "affected"
      },
      {
        "version": "16.5.1a",
        "status": "affected"
      },
      {
        "version": "16.5.1b",
        "status": "affected"
      },
      {
        "version": "16.5.2",
        "status": "affected"
      },
      {
        "version": "16.5.3",
        "status": "affected"
      },
      {
        "version": "16.6.1",
        "status": "affected"
      },
      {
        "version": "16.6.2",
        "status": "affected"
      },
      {
        "version": "16.6.3",
        "status": "affected"
      },
      {
        "version": "16.6.4",
        "status": "affected"
      },
      {
        "version": "16.6.5",
        "status": "affected"
      },
      {
        "version": "16.6.4a",
        "status": "affected"
      },
      {
        "version": "16.6.5a",
        "status": "affected"
      },
      {
        "version": "16.6.6",
        "status": "affected"
      },
      {
        "version": "16.6.7",
        "status": "affected"
      },
      {
        "version": "16.6.8",
        "status": "affected"
      },
      {
        "version": "16.6.9",
        "status": "affected"
      },
      {
        "version": "16.6.10",
        "status": "affected"
      },
      {
        "version": "16.7.1",
        "status": "affected"
      },
      {
        "version": "16.7.1a",
        "status": "affected"
      },
      {
        "version": "16.7.1b",
        "status": "affected"
      },
      {
        "version": "16.7.2",
        "status": "affected"
      },
      {
        "version": "16.7.3",
        "status": "affected"
      },
      {
        "version": "16.7.4",
        "status": "affected"
      },
      {
        "version": "16.8.1",
        "status": "affected"
      },
      {
        "version": "16.8.1a",
        "status": "affected"
      },
      {
        "version": "16.8.1b",
        "status": "affected"
      },
      {
        "version": "16.8.1s",
        "status": "affected"
      },
      {
        "version": "16.8.1c",
        "status": "affected"
      },
      {
        "version": "16.8.1d",
        "status": "affected"
      },
      {
        "version": "16.8.2",
        "status": "affected"
      },
      {
        "version": "16.8.1e",
        "status": "affected"
      },
      {
        "version": "16.8.3",
        "status": "affected"
      },
      {
        "version": "16.9.1",
        "status": "affected"
      },
      {
        "version": "16.9.2",
        "status": "affected"
      },
      {
        "version": "16.9.1a",
        "status": "affected"
      },
      {
        "version": "16.9.1b",
        "status": "affected"
      },
      {
        "version": "16.9.1s",
        "status": "affected"
      },
      {
        "version": "16.9.3",
        "status": "affected"
      },
      {
        "version": "16.9.4",
        "status": "affected"
      },
      {
        "version": "16.9.3a",
        "status": "affected"
      },
      {
        "version": "16.9.5",
        "status": "affected"
      },
      {
        "version": "16.9.5f",
        "status": "affected"
      },
      {
        "version": "16.9.6",
        "status": "affected"
      },
      {
        "version": "16.9.7",
        "status": "affected"
      },
      {
        "version": "16.9.8",
        "status": "affected"
      },
      {
        "version": "16.10.1",
        "status": "affected"
      },
      {
        "version": "16.10.1a",
        "status": "affected"
      },
      {
        "version": "16.10.1b",
        "status": "affected"
      },
      {
        "version": "16.10.1s",
        "status": "affected"
      },
      {
        "version": "16.10.1c",
        "status": "affected"
      },
      {
        "version": "16.10.1e",
        "status": "affected"
      },
      {
        "version": "16.10.1d",
        "status": "affected"
      },
      {
        "version": "16.10.2",
        "status": "affected"
      },
      {
        "version": "16.10.1f",
        "status": "affected"
      },
      {
        "version": "16.10.1g",
        "status": "affected"
      },
      {
        "version": "16.10.3",
        "status": "affected"
      },
      {
        "version": "16.11.1",
        "status": "affected"
      },
      {
        "version": "16.11.1a",
        "status": "affected"
      },
      {
        "version": "16.11.1b",
        "status": "affected"
      },
      {
        "version": "16.11.2",
        "status": "affected"
      },
      {
        "version": "16.11.1s",
        "status": "affected"
      },
      {
        "version": "16.12.1",
        "status": "affected"
      },
      {
        "version": "16.12.1s",
        "status": "affected"
      },
      {
        "version": "16.12.1a",
        "status": "affected"
      },
      {
        "version": "16.12.1c",
        "status": "affected"
      },
      {
        "version": "16.12.1w",
        "status": "affected"
      },
      {
        "version": "16.12.2",
        "status": "affected"
      },
      {
        "version": "16.12.1y",
        "status": "affected"
      },
      {
        "version": "16.12.2a",
        "status": "affected"
      },
      {
        "version": "16.12.3",
        "status": "affected"
      },
      {
        "version": "16.12.8",
        "status": "affected"
      },
      {
        "version": "16.12.2s",
        "status": "affected"
      },
      {
        "version": "16.12.1x",
        "status": "affected"
      },
      {
        "version": "16.12.1t",
        "status": "affected"
      },
      {
        "version": "16.12.4",
        "status": "affected"
      },
      {
        "version": "16.12.3s",
        "status": "affected"
      },
      {
        "version": "16.12.3a",
        "status": "affected"
      },
      {
        "version": "16.12.4a",
        "status": "affected"
      },
      {
        "version": "16.12.5",
        "status": "affected"
      },
      {
        "version": "16.12.6",
        "status": "affected"
      },
      {
        "version": "16.12.1z1",
        "status": "affected"
      },
      {
        "version": "16.12.5a",
        "status": "affected"
      },
      {
        "version": "16.12.5b",
        "status": "affected"
      },
      {
        "version": "16.12.1z2",
        "status": "affected"
      },
      {
        "version": "16.12.6a",
        "status": "affected"
      },
      {
        "version": "16.12.7",
        "status": "affected"
      },
      {
        "version": "16.12.9",
        "status": "affected"
      },
      {
        "version": "16.12.10",
        "status": "affected"
      },
      {
        "version": "17.1.1",
        "status": "affected"
      },
      {
        "version": "17.1.1a",
        "status": "affected"
      },
      {
        "version": "17.1.1s",
        "status": "affected"
      },
      {
        "version": "17.1.1t",
        "status": "affected"
      },
      {
        "version": "17.1.3",
        "status": "affected"
      },
      {
        "version": "17.2.1",
        "status": "affected"
      },
      {
        "version": "17.2.1r",
        "status": "affected"
      },
      {
        "version": "17.2.1a",
        "status": "affected"
      },
      {
        "version": "17.2.1v",
        "status": "affected"
      },
      {
        "version": "17.2.2",
        "status": "affected"
      },
      {
        "version": "17.2.3",
        "status": "affected"
      },
      {
        "version": "17.3.1",
        "status": "affected"
      },
      {
        "version": "17.3.2",
        "status": "affected"
      },
      {
        "version": "17.3.3",
        "status": "affected"
      },
      {
        "version": "17.3.1a",
        "status": "affected"
      },
      {
        "version": "17.3.1w",
        "status": "affected"
      },
      {
        "version": "17.3.2a",
        "status": "affected"
      },
      {
        "version": "17.3.1x",
        "status": "affected"
      },
      {
        "version": "17.3.1z",
        "status": "affected"
      },
      {
        "version": "17.3.4",
        "status": "affected"
      },
      {
        "version": "17.3.5",
        "status": "affected"
      },
      {
        "version": "17.3.4a",
        "status": "affected"
      },
      {
        "version": "17.3.6",
        "status": "affected"
      },
      {
        "version": "17.3.4b",
        "status": "affected"
      },
      {
        "version": "17.3.4c",
        "status": "affected"
      },
      {
        "version": "17.3.5a",
        "status": "affected"
      },
      {
        "version": "17.3.5b",
        "status": "affected"
      },
      {
        "version": "17.3.7",
        "status": "affected"
      },
      {
        "version": "17.3.8",
        "status": "affected"
      },
      {
        "version": "17.4.1",
        "status": "affected"
      },
      {
        "version": "17.4.2",
        "status": "affected"
      },
      {
        "version": "17.4.1a",
        "status": "affected"
      },
      {
        "version": "17.4.1b",
        "status": "affected"
      },
      {
        "version": "17.4.2a",
        "status": "affected"
      },
      {
        "version": "17.5.1",
        "status": "affected"
      },
      {
        "version": "17.5.1a",
        "status": "affected"
      },
      {
        "version": "17.5.1b",
        "status": "affected"
      },
      {
        "version": "17.5.1c",
        "status": "affected"
      },
      {
        "version": "17.6.1",
        "status": "affected"
      },
      {
        "version": "17.6.2",
        "status": "affected"
      },
      {
        "version": "17.6.1w",
        "status": "affected"
      },
      {
        "version": "17.6.1a",
        "status": "affected"
      },
      {
        "version": "17.6.1x",
        "status": "affected"
      },
      {
        "version": "17.6.3",
        "status": "affected"
      },
      {
        "version": "17.6.1y",
        "status": "affected"
      },
      {
        "version": "17.6.1z",
        "status": "affected"
      },
      {
        "version": "17.6.3a",
        "status": "affected"
      },
      {
        "version": "17.6.4",
        "status": "affected"
      },
      {
        "version": "17.6.1z1",
        "status": "affected"
      },
      {
        "version": "17.6.5",
        "status": "affected"
      },
      {
        "version": "17.6.6",
        "status": "affected"
      },
      {
        "version": "17.7.1",
        "status": "affected"
      },
      {
        "version": "17.7.1a",
        "status": "affected"
      },
      {
        "version": "17.7.1b",
        "status": "affected"
      },
      {
        "version": "17.7.2",
        "status": "affected"
      },
      {
        "version": "17.10.1",
        "status": "affected"
      },
      {
        "version": "17.10.1a",
        "status": "affected"
      },
      {
        "version": "17.10.1b",
        "status": "affected"
      },
      {
        "version": "17.8.1",
        "status": "affected"
      },
      {
        "version": "17.8.1a",
        "status": "affected"
      },
      {
        "version": "17.9.1",
        "status": "affected"
      },
      {
        "version": "17.9.1w",
        "status": "affected"
      },
      {
        "version": "17.9.2",
        "status": "affected"
      },
      {
        "version": "17.9.1a",
        "status": "affected"
      },
      {
        "version": "17.9.1x",
        "status": "affected"
      },
      {
        "version": "17.9.1y",
        "status": "affected"
      },
      {
        "version": "17.9.3",
        "status": "affected"
      },
      {
        "version": "17.9.2a",
        "status": "affected"
      },
      {
        "version": "17.9.1x1",
        "status": "affected"
      },
      {
        "version": "17.9.3a",
        "status": "affected"
      },
      {
        "version": "17.9.4",
        "status": "affected"
      },
      {
        "version": "17.9.1y1",
        "status": "affected"
      },
      {
        "version": "17.11.1",
        "status": "affected"
      },
      {
        "version": "17.11.1a",
        "status": "affected"
      },
      {
        "version": "17.12.1",
        "status": "affected"
      },
      {
        "version": "17.12.1a",
        "status": "affected"
      },
      {
        "version": "17.11.99SW",
        "status": "affected"
      }
    ]
  }
]

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

8.7 High

AI Score

Confidence

High

0.853 High

EPSS

Percentile

98.6%