PromptRiskDBThreat intelligence atlas

CVE-2023-20273 - Cisco Cisco IOS XE Web UI

AI Vulnerability Context

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privi...

Overview

A source-backed snapshot of this vulnerability.

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVHIGH
CVE ID
CVE-2023-20273
Vendor/project
Cisco
Product
Cisco IOS XE Web UI
Vulnerability name
Cisco IOS XE Web UI Command Injection Vulnerability
Date added
2023-10-23
Due date
2023-10-27
Known ransomware campaign use
Unknown
CVSS v3
7.2
CWE-78

Exploit context

What the vulnerability is about.

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.