Improper Privilege Management in Cisco IOS XE - CVE-2023-20198
Published: October 17, 2023 / Updated: April 18, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper privilege management in the web UI feature. A remote non-authenticated attacker can send a specially crafted HTTP request to the affected device and create an account with privilege level 15 access.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Stratix 5800
Stratix 5200
How to mitigate CVE-2023-20198
Links to Public Exploits and PoC-codes
- Exploit #11315 - Cisco-IOS-XE-CVE-2023-20198 (Exploit PoC for CVE-2023-20198) (April 18, 2025)
- Exploit #10920 - cve-2023-20198-poc (CVE-2023-20198是思科IOS XE软件Web UI功能中的一个严重漏洞,允许未经身份验证的远程攻击者在受影响的系统上创建具有特权级别15的账户,从而完全控制设备。) (November 29, 2024)
- Exploit #10851 - CVE-2023-20198-Scanner (This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273) (November 8, 2024)
- Exploit #10215 - Simple-Ansible-for-CVE-2023-20198 () (July 19, 2024)
- Exploit #10183 - CVE-2023-20198 (An Exploitation script developed to exploit the CVE-2023-20198 Cisco zero day vulnerability on their IOS routers ) (July 5, 2024)
- Exploit #10113 - CVE-2023-20198 (CISCO CVE POC SCRIPT) (June 21, 2024)
- Exploit #9748 - CVE-2023-20198-RCE (CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.) (April 26, 2024)
- Exploit #9435 - CVE-2023-20198 (CVE-2023-20198 Exploit PoC) (December 18, 2023)
- Exploit #9406 - Cisco IOX XE Unauthenticated RCE Chain (November 8, 2023)
- Exploit #9408 - Cisco IOX XE unauthenticated OS command execution (November 8, 2023)
- Exploit #9409 - Cisco IOX XE unauthenticated Command Line Interface (CLI) execution (November 8, 2023)
- Exploit #9397 - Cisco IOS XE CVE-2023-20198: Deep Dive and POC (October 31, 2023)
External References
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh87343
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z
- https://www.horizon3.ai/cisco-ios-xe-cve-2023-20198-theory-crafting/
- https://www.horizon3.ai/cisco-ios-xe-cve-2023-20198-deep-dive-and-poc/