CVE-2023-20198
Cisco IOS XE Web UI Privilege Escalation Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 10
- EPSS
- 99.6% 백분위 99.9% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2023.10.20
- 공개일
- 2023.10.17
CISA KEV에 등록된 실제 악용 확인 취약점
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new lo...
공급사 Cisco
제품 IOS XE Web UI
영향 버전 16.1.1, 16.1.2, 16.1.3, 16.2.1, 16.2.2, 16.3.1, 16.3.2, 16.3.3, 16.3.1a, 16.3.4, 16.3.5, 16.3.5b, 16.3.6, 16.3.7, 16.3.8, 16.3.9, 16.3.10, 16.3.11, 16.4.1, 16.4.2
수정 버전 17.12.02, 16.12.10a, 17.3.8a, 17.6.6a, 17.9.4a
Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.
조치 기한: 2023.10.20CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE CWE-420
KEV 등록일 2023.10.16
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-xe-dublin-17121/221128-software-fix-availability-for-cisco-ios.html; https://nvd.nist.gov/vuln/detail/CVE-2023-20198
EPSS 데이터 기준일 2026.06.27