CVE-2023-20198
Cisco IOS XE Web UI Privilege Escalation Vulnerability
- Published
- Oct 16, 2023
- Updated
- Oct 21, 2025
- Assigning CNA
- cisco
- Evidence observed
- Oct 16, 2023
Cisco IOS XE Web UI Privilege Escalation Vulnerability
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.
Scans Cisco IOS XE devices for CVE-2023-20198 Web UI authentication vulnerability using curl payloads, detects HTTP 200 responses, and saves detailed results.
CVE-2023-20198 Checkscript
Analysis, detection, and mitigation of CVE-2023-20198 exploitation in Cisco IOS XE – QUB CSC3064 Network Security Assessment
Exploit PoC for CVE-2023-20198
Proof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI
Go-based vulnerability scanner for detecting CVE-2023-20198 in Cisco IOS XE devices. Tests SOAP/XML interfaces (WSMA) for remote code execution with batch scanning and HTML report generation.
Multi-threaded scanner for detecting CVE-2023-20198 critical vulnerability in Cisco IOS XE Web UI, identifying unauthorized level 15 access and potential implants.
1vere$k POC on the CVE-2023-20198
Checker for CVE-2023-20198 , Not a full POC Just checks the implementation and detects if hex is in response or not
Check a target IP for CVE-2023-20198 vulnerability in Cisco IOS XE web UI. Simple Python script for rapid exploitation verification.
Single-threaded PowerShell PoC scanner for CVE-2023-20198 targeting Cisco IOS XE devices. Quick proof-of-concept for vulnerability detection and implant identification.
A PoC for CVE 2023-20198
Python script to scan networks for Cisco IOS XE devices vulnerable to CVE-2023-20198, detecting implants via HTTP status and response analysis.
An Exploitation script developed to exploit the CVE-2023-20198 Cisco zero day vulnerability on their IOS routers
Proof-of-concept exploit for CVE-2023-20198 targeting Cisco IOS XE Web UI. Enables unauthenticated remote command execution, configuration retrieval, and privilege escalation via SOAP endpoints.
cisco-CVE-2023-20198-tester
CVE-2023-20198 Exploit PoC
CISCO CVE POC SCRIPT
Cisco CVE-2023-20198
CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.
CVE-2023-20198 & 0Day Implant Scanner
Exploit for CVE-2023-20198, a critical privilege escalation vulnerability in Cisco IOS XE web UI, enabling unauthorized access and remote code execution.
Python-based exploit tool for CVE-2023-20198 targeting Cisco IOS XE routers. Provides automated exploitation and post-exploitation capabilities for penetration testing.
CVE-2023-20198是思科IOS XE软件Web UI功能中的一个严重漏洞,允许未经身份验证的远程攻击者在受影响的系统上创建具有特权级别15的账户,从而完全控制设备。
CVE-2023-20198 PoC (!)
CVE proof-of-concept labs, exploit scripts, and detection/prevention rules (Nginx, Apache, Snort, YARA) for high-severity CVEs. Authorized security testing & research only.
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.