CVE-2023-20273

Cisco IOS XE Web UI: Command Injection

As of , CVE-2023-20273 in Cisco IOS XE Web UI is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 23 October 2023
US federal deadline
27 October 20234 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.90Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
No score that dayThe EPSS file of the day CISA listed it has no score for it.
Public exploit
2 Metasploit modules
Fix
Vendor advice: sec.cloudapps.cisco.comLinks below, from CISA's entry.

What CISA says to do

Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.

CISA's required action

What the flaw is

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

CISA's description

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

The CVE record's description, from cisco

CVE published
24 October 2023
Assigned by
cisco
CVSS
7.2 High (CVSS 3.1, from the CNA)
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. CISA added it to its list of exploited vulnerabilities.
  2. The CVE record was published.
  3. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Read further