CVE-2023-20273
Cisco IOS XE Web UI: Command Injection
As of , CVE-2023-20273 in Cisco IOS XE Web UI is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 23 October 2023
- US federal deadline
- 27 October 20234 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.90Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- No score that dayThe EPSS file of the day CISA listed it has no score for it.
- Public exploit
- 2 Metasploit modules
- Fix
- Vendor advice: sec.cloudapps.cisco.comLinks below, from CISA's entry.
What CISA says to do
Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.
CISA's required action
What the flaw is
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.
CISA's description
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
The CVE record's description, from cisco
- CVE published
- 24 October 2023
- Assigned by
- cisco
- CVSS
- 7.2 High (CVSS 3.1, from the CNA)
- CWE-78
- Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- CISA added it to its list of exploited vulnerabilities.
- The CVE record was published.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: Cisco IOX XE Unauthenticated RCE Chainexploit module, rank excellent
- Metasploit: Cisco IOX XE unauthenticated OS command executionauxiliary module, rank normal
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org