S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2023-20198 Scanner

CVE-2023-20198 scanner - Authentication Bypass vulnerability in Cisco IOS XE

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
4
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-20198
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Cisco IOS XE Softwareby Cisco
16.1.1
Updated Aug 19, 2026View on NVD →
Detail

Cisco IOS XE is a highly flexible and feature-rich network operating system that powers a wide range of enterprise and service provider networking solutions. It is designed to provide high availability, comprehensive security, and simplified management. This operating system is deployed on various Cisco devices, including routers and switches, to facilitate secure and efficient data communication across networks. Given its critical role in network infrastructure, vulnerabilities in Cisco IOS XE can have significant implications for network security and integrity.

CVE-2023-20198 is a critical vulnerability in the web UI feature of Cisco IOS XE Software, identified as an authentication bypass issue. This vulnerability allows remote, unauthenticated attackers to create a high-privilege account on affected systems, providing them with level 15 access. Such access could enable attackers to gain full control over the device and potentially the entire network, posing a severe security risk.

The vulnerability stems from improper authorization enforcement mechanisms within the web-based management interface of Cisco IOS XE. Attackers can exploit this flaw by sending a specially crafted HTTP request to an affected device. The exploitation does not require any form of authentication or user interaction, making it particularly dangerous and easy to exploit on devices exposed to the internet or untrusted networks.

Successful exploitation of CVE-2023-20198 could result in unauthorized access to the affected system, allowing attackers to execute arbitrary commands, alter configurations, disrupt services, or gain access to sensitive data. Given the critical nature of devices running Cisco IOS XE, this could lead to significant operational impact, including network downtime, data breaches, and a compromise of network security.

S4E offers a cutting-edge platform designed to detect and manage vulnerabilities like CVE-2023-20198 in Cisco IOS XE. Our service provides detailed vulnerability assessments, real-time monitoring, and actionable remediation advice, empowering organizations to safeguard their network infrastructure against emerging threats. By subscribing to S4E, you benefit from comprehensive cyber threat exposure management, ensuring your network remains secure and resilient against sophisticated cyber attacks.

 

References

Solution Advice
  1. Immediately apply any available security updates or patches from Cisco for CVE-2023-20198.
  2. Restrict access to the web UI of the affected Cisco IOS XE devices from the internet and untrusted networks.
  3. Monitor network traffic for signs of exploitation attempts against the vulnerability.
  4. Regularly review system logs for unauthorized access attempts or suspicious activities.
  5. Consider implementing additional network security measures, such as firewalls and intrusion detection/prevention systems, to further protect the network infrastructure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-20198 scanner - Authentication Bypass vulnerability in Cisco IOS XE | S4E