Skip to content
COOEY

EXPOSURES › CVE-2023-20273

CVE-2023-20273

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-10-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-20273 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Cisco IOS XE Web UI Command Injection Vulnerability

Cisco IOS XE Web UI contains a command injection vulnerability that can be exploited to elevate privileges to root and deploy implants. This vulnerability is actively exploited and poses a significant risk to network security. DIB organizations should ensure they are using the latest patches and monitor for any signs of exploitation.

Shame score — The vulnerability is actively exploited and allows for remote code execution, leading to potential data compromise and system compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized