EXPOSURES › CVE-2023-20198
CVE-2023-20198
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco IOS XE Web UI privilege escalation vulnerability allows remote, unauthenticated attackers to gain control of devices.
Cisco IOS XE Web UI contains a privilege escalation vulnerability that allows remote, unauthenticated attackers to create an account with privilege level 15 access, enabling control of the affected device. This vulnerability poses a significant risk to network security and should be addressed promptly to prevent unauthorized access and potential device compromise.
Shame score — The vulnerability is actively exploited and allows remote, unauthenticated attackers to gain control of devices, which is a severe security risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |