7.2

CVE-2023-20273

Warning

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version16.1.1
CiscoIos Xe Version16.1.2
CiscoIos Xe Version16.1.3
CiscoIos Xe Version16.2.1
CiscoIos Xe Version16.2.2
CiscoIos Xe Version16.3.1a
CiscoIos Xe Version16.3.2
CiscoIos Xe Version16.3.3
CiscoIos Xe Version16.3.4
CiscoIos Xe Version16.3.5
CiscoIos Xe Version16.3.5b
CiscoIos Xe Version16.3.6
CiscoIos Xe Version16.3.7
CiscoIos Xe Version16.3.8
CiscoIos Xe Version16.3.9
CiscoIos Xe Version16.3.10
CiscoIos Xe Version16.3.11
CiscoIos Xe Version16.4.1
CiscoIos Xe Version16.4.2
CiscoIos Xe Version16.4.3
CiscoIos Xe Version16.5.1
CiscoIos Xe Version16.5.1a
CiscoIos Xe Version16.5.1b
CiscoIos Xe Version16.5.2
CiscoIos Xe Version16.5.3
CiscoIos Xe Version16.6.1
CiscoIos Xe Version16.6.2
CiscoIos Xe Version16.6.3
CiscoIos Xe Version16.6.4
CiscoIos Xe Version16.6.4a
CiscoIos Xe Version16.6.5
CiscoIos Xe Version16.6.5a
CiscoIos Xe Version16.6.6
CiscoIos Xe Version16.6.7
CiscoIos Xe Version16.6.8
CiscoIos Xe Version16.6.9
CiscoIos Xe Version16.6.10
CiscoIos Xe Version16.7.1
CiscoIos Xe Version16.7.1a
CiscoIos Xe Version16.7.1b
CiscoIos Xe Version16.7.2
CiscoIos Xe Version16.7.3
CiscoIos Xe Version16.7.4
CiscoIos Xe Version16.8.1
CiscoIos Xe Version16.8.1a
CiscoIos Xe Version16.8.1b
CiscoIos Xe Version16.8.1c
CiscoIos Xe Version16.8.1d
CiscoIos Xe Version16.8.1e
CiscoIos Xe Version16.8.1s
CiscoIos Xe Version16.8.2
CiscoIos Xe Version16.8.3
CiscoIos Xe Version16.9.1
CiscoIos Xe Version16.9.1a
CiscoIos Xe Version16.9.1b
CiscoIos Xe Version16.9.1s
CiscoIos Xe Version16.9.2
CiscoIos Xe Version16.9.3
CiscoIos Xe Version16.9.3a
CiscoIos Xe Version16.9.4
CiscoIos Xe Version16.9.5
CiscoIos Xe Version16.9.5f
CiscoIos Xe Version16.9.6
CiscoIos Xe Version16.9.7
CiscoIos Xe Version16.9.8
CiscoIos Xe Version16.10.1
CiscoIos Xe Version16.10.1a
CiscoIos Xe Version16.10.1b
CiscoIos Xe Version16.10.1c
CiscoIos Xe Version16.10.1d
CiscoIos Xe Version16.10.1e
CiscoIos Xe Version16.10.1f
CiscoIos Xe Version16.10.1g
CiscoIos Xe Version16.10.1s
CiscoIos Xe Version16.10.2
CiscoIos Xe Version16.10.3
CiscoIos Xe Version16.11.1
CiscoIos Xe Version16.11.1a
CiscoIos Xe Version16.11.1b
CiscoIos Xe Version16.11.1s
CiscoIos Xe Version16.11.2
CiscoIos Xe Version16.12.1
CiscoIos Xe Version16.12.1a
CiscoIos Xe Version16.12.1c
CiscoIos Xe Version16.12.1s
CiscoIos Xe Version16.12.1t
CiscoIos Xe Version16.12.1w
CiscoIos Xe Version16.12.1x
CiscoIos Xe Version16.12.1y
CiscoIos Xe Version16.12.1z1
CiscoIos Xe Version16.12.1z2
CiscoIos Xe Version16.12.2
CiscoIos Xe Version16.12.2a
CiscoIos Xe Version16.12.2s
CiscoIos Xe Version16.12.3
CiscoIos Xe Version16.12.3a
CiscoIos Xe Version16.12.3s
CiscoIos Xe Version16.12.4
CiscoIos Xe Version16.12.4a
CiscoIos Xe Version16.12.5
CiscoIos Xe Version16.12.5a
CiscoIos Xe Version16.12.5b
CiscoIos Xe Version16.12.6
CiscoIos Xe Version16.12.6a
CiscoIos Xe Version16.12.7
CiscoIos Xe Version16.12.8
CiscoIos Xe Version16.12.9
CiscoIos Xe Version16.12.10
CiscoIos Xe Version17.1.1
CiscoIos Xe Version17.1.1a
CiscoIos Xe Version17.1.1s
CiscoIos Xe Version17.1.1t
CiscoIos Xe Version17.1.3
CiscoIos Xe Version17.2.1
CiscoIos Xe Version17.2.1a
CiscoIos Xe Version17.2.1r
CiscoIos Xe Version17.2.1v
CiscoIos Xe Version17.2.2
CiscoIos Xe Version17.2.3
CiscoIos Xe Version17.3.1
CiscoIos Xe Version17.3.1a
CiscoIos Xe Version17.3.1w
CiscoIos Xe Version17.3.1x
CiscoIos Xe Version17.3.1z
CiscoIos Xe Version17.3.2
CiscoIos Xe Version17.3.2a
CiscoIos Xe Version17.3.3
CiscoIos Xe Version17.3.4
CiscoIos Xe Version17.3.4a
CiscoIos Xe Version17.3.4b
CiscoIos Xe Version17.3.4c
CiscoIos Xe Version17.3.5
CiscoIos Xe Version17.3.5a
CiscoIos Xe Version17.3.5b
CiscoIos Xe Version17.3.6
CiscoIos Xe Version17.3.7
CiscoIos Xe Version17.3.8
CiscoIos Xe Version17.4.1
CiscoIos Xe Version17.4.1a
CiscoIos Xe Version17.4.1b
CiscoIos Xe Version17.4.2
CiscoIos Xe Version17.4.2a
CiscoIos Xe Version17.5.1
CiscoIos Xe Version17.5.1a
CiscoIos Xe Version17.5.1b
CiscoIos Xe Version17.5.1c
CiscoIos Xe Version17.6.1
CiscoIos Xe Version17.6.1a
CiscoIos Xe Version17.6.1w
CiscoIos Xe Version17.6.1x
CiscoIos Xe Version17.6.1y
CiscoIos Xe Version17.6.1z
CiscoIos Xe Version17.6.1z1
CiscoIos Xe Version17.6.2
CiscoIos Xe Version17.6.3
CiscoIos Xe Version17.6.3a
CiscoIos Xe Version17.6.4
CiscoIos Xe Version17.6.5
CiscoIos Xe Version17.6.6
CiscoIos Xe Version17.7.1
CiscoIos Xe Version17.7.1a
CiscoIos Xe Version17.7.1b
CiscoIos Xe Version17.7.2
CiscoIos Xe Version17.8.1
CiscoIos Xe Version17.8.1a
CiscoIos Xe Version17.9.1
CiscoIos Xe Version17.9.1a
CiscoIos Xe Version17.9.1w
CiscoIos Xe Version17.9.1x
CiscoIos Xe Version17.9.1x1
CiscoIos Xe Version17.9.1y
CiscoIos Xe Version17.9.1y1
CiscoIos Xe Version17.9.2
CiscoIos Xe Version17.9.2a
CiscoIos Xe Version17.9.3
CiscoIos Xe Version17.9.3a
CiscoIos Xe Version17.9.4
CiscoIos Xe Version17.10.1
CiscoIos Xe Version17.10.1a
CiscoIos Xe Version17.10.1b
CiscoIos Xe Version17.11.1
CiscoIos Xe Version17.11.1a
CiscoIos Xe Version17.11.99sw
CiscoIos Xe Version17.12.1
CiscoIos Xe Version17.12.1a
CiscoIos Xe Version >= 17.3 < 17.3.8a
CiscoIos Xe Version >= 17.6 < 17.6.6a
CiscoIos Xe Version >= 17.9 < 17.9.4a
CiscoIos Xe Version >= 16.12 < 16.12.10a
   CiscoCatalyst 3650 Version-
   CiscoCatalyst 3650-12x48fd-e Version-
   CiscoCatalyst 3650-12x48fd-l Version-
   CiscoCatalyst 3650-12x48fd-s Version-
   CiscoCatalyst 3650-12x48uq Version-
   CiscoCatalyst 3650-12x48uq-e Version-
   CiscoCatalyst 3650-12x48uq-l Version-
   CiscoCatalyst 3650-12x48uq-s Version-
   CiscoCatalyst 3650-12x48ur Version-
   CiscoCatalyst 3650-12x48ur-e Version-
   CiscoCatalyst 3650-12x48ur-l Version-
   CiscoCatalyst 3650-12x48ur-s Version-
   CiscoCatalyst 3650-12x48uz Version-
   CiscoCatalyst 3650-12x48uz-e Version-
   CiscoCatalyst 3650-12x48uz-l Version-
   CiscoCatalyst 3650-12x48uz-s Version-
   CiscoCatalyst 3650-24pd Version-
   CiscoCatalyst 3650-24pd-e Version-
   CiscoCatalyst 3650-24pd-l Version-
   CiscoCatalyst 3650-24pd-s Version-
   CiscoCatalyst 3650-24pdm Version-
   CiscoCatalyst 3650-24pdm-e Version-
   CiscoCatalyst 3650-24pdm-l Version-
   CiscoCatalyst 3650-24pdm-s Version-
   CiscoCatalyst 3650-24ps-e Version-
   CiscoCatalyst 3650-24ps-l Version-
   CiscoCatalyst 3650-24ps-s Version-
   CiscoCatalyst 3650-24td-e Version-
   CiscoCatalyst 3650-24td-l Version-
   CiscoCatalyst 3650-24td-s Version-
   CiscoCatalyst 3650-24ts-e Version-
   CiscoCatalyst 3650-24ts-l Version-
   CiscoCatalyst 3650-24ts-s Version-
   CiscoCatalyst 3650-48fd-e Version-
   CiscoCatalyst 3650-48fd-l Version-
   CiscoCatalyst 3650-48fd-s Version-
   CiscoCatalyst 3650-48fq Version-
   CiscoCatalyst 3650-48fq-e Version-
   CiscoCatalyst 3650-48fq-l Version-
   CiscoCatalyst 3650-48fq-s Version-
   CiscoCatalyst 3650-48fqm Version-
   CiscoCatalyst 3650-48fqm-e Version-
   CiscoCatalyst 3650-48fqm-l Version-
   CiscoCatalyst 3650-48fqm-s Version-
   CiscoCatalyst 3650-48fs-e Version-
   CiscoCatalyst 3650-48fs-l Version-
   CiscoCatalyst 3650-48fs-s Version-
   CiscoCatalyst 3650-48pd-e Version-
   CiscoCatalyst 3650-48pd-l Version-
   CiscoCatalyst 3650-48pd-s Version-
   CiscoCatalyst 3650-48pq-e Version-
   CiscoCatalyst 3650-48pq-l Version-
   CiscoCatalyst 3650-48pq-s Version-
   CiscoCatalyst 3650-48ps-e Version-
   CiscoCatalyst 3650-48ps-l Version-
   CiscoCatalyst 3650-48ps-s Version-
   CiscoCatalyst 3650-48td-e Version-
   CiscoCatalyst 3650-48td-l Version-
   CiscoCatalyst 3650-48td-s Version-
   CiscoCatalyst 3650-48tq-e Version-
   CiscoCatalyst 3650-48tq-l Version-
   CiscoCatalyst 3650-48tq-s Version-
   CiscoCatalyst 3650-48ts-e Version-
   CiscoCatalyst 3650-48ts-l Version-
   CiscoCatalyst 3650-48ts-s Version-
   CiscoCatalyst 3650-8x24pd-e Version-
   CiscoCatalyst 3650-8x24pd-l Version-
   CiscoCatalyst 3650-8x24pd-s Version-
   CiscoCatalyst 3650-8x24uq Version-
   CiscoCatalyst 3650-8x24uq-e Version-
   CiscoCatalyst 3650-8x24uq-l Version-
   CiscoCatalyst 3650-8x24uq-s Version-
   CiscoCatalyst 3850 Version-
   CiscoCatalyst 3850-12s-e Version-
   CiscoCatalyst 3850-12s-s Version-
   CiscoCatalyst 3850-12x48u Version-
   CiscoCatalyst 3850-12xs-e Version-
   CiscoCatalyst 3850-12xs-s Version-
   CiscoCatalyst 3850-16xs-e Version-
   CiscoCatalyst 3850-16xs-s Version-
   CiscoCatalyst 3850-24p-e Version-
   CiscoCatalyst 3850-24p-l Version-
   CiscoCatalyst 3850-24p-s Version-
   CiscoCatalyst 3850-24pw-s Version-
   CiscoCatalyst 3850-24s-e Version-
   CiscoCatalyst 3850-24s-s Version-
   CiscoCatalyst 3850-24t-e Version-
   CiscoCatalyst 3850-24t-l Version-
   CiscoCatalyst 3850-24t-s Version-
   CiscoCatalyst 3850-24u Version-
   CiscoCatalyst 3850-24u-e Version-
   CiscoCatalyst 3850-24u-l Version-
   CiscoCatalyst 3850-24u-s Version-
   CiscoCatalyst 3850-24xs Version-
   CiscoCatalyst 3850-24xs-e Version-
   CiscoCatalyst 3850-24xs-s Version-
   CiscoCatalyst 3850-24xu Version-
   CiscoCatalyst 3850-24xu-e Version-
   CiscoCatalyst 3850-24xu-l Version-
   CiscoCatalyst 3850-24xu-s Version-
   CiscoCatalyst 3850-32xs-e Version-
   CiscoCatalyst 3850-32xs-s Version-
   CiscoCatalyst 3850-48f-e Version-
   CiscoCatalyst 3850-48f-l Version-
   CiscoCatalyst 3850-48f-s Version-
   CiscoCatalyst 3850-48p-e Version-
   CiscoCatalyst 3850-48p-l Version-
   CiscoCatalyst 3850-48p-s Version-
   CiscoCatalyst 3850-48pw-s Version-
   CiscoCatalyst 3850-48t-e Version-
   CiscoCatalyst 3850-48t-l Version-
   CiscoCatalyst 3850-48t-s Version-
   CiscoCatalyst 3850-48u Version-
   CiscoCatalyst 3850-48u-e Version-
   CiscoCatalyst 3850-48u-l Version-
   CiscoCatalyst 3850-48u-s Version-
   CiscoCatalyst 3850-48xs Version-
   CiscoCatalyst 3850-48xs-e Version-
   CiscoCatalyst 3850-48xs-f-e Version-
   CiscoCatalyst 3850-48xs-f-s Version-
   CiscoCatalyst 3850-48xs-s Version-
   CiscoCatalyst 3850-nm-2-40g Version-
   CiscoCatalyst 3850-nm-8-10g Version-

23.10.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Cisco IOS XE Web UI Command Injection Vulnerability

Vulnerability

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

Description

Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 92.04% 0.997
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@cisco.com 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.