Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-20198

Quick assessment

Affected
Cisco Cisco IOS XE Software
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cisco IOS XE Software是美国思科(Cisco)公司的一个操作系统。用于企业有线和无线访问,汇聚,核心和WAN的单一操作系统,Cisco IOS XE降低了业务和网络的复杂性。 Cisco IOS XE Software 存在安全漏洞,该漏洞源于允许未经身份验证的远程攻击者在受影响的系统上创建具有特权的帐户。

CVSS 10.0 · Critical KEV EPSS 99.57% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-20198

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未保护的候选通道
Source: CVE Program / CVE List V5
Vulnerability Title
Cisco IOS XE Software 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco IOS XE Software是美国思科(Cisco)公司的一个操作系统。用于企业有线和无线访问,汇聚,核心和WAN的单一操作系统,Cisco IOS XE降低了业务和网络的复杂性。 Cisco IOS XE Software 存在安全漏洞,该漏洞源于允许未经身份验证的远程攻击者在受影响的系统上创建具有特权的帐户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cisco Cisco IOS XE Software 16.1.1 -

II. Public POCs for CVE-2023-20198

# POC Description Source Link Shenlong Link
1 None https://github.com/raystr-atearedteam/CVE-2023-20198-checker POC Details
2 CVE-2023-20198 Checkscript https://github.com/Atea-Redteam/CVE-2023-20198 POC Details
3 cisco-CVE-2023-20198-tester https://github.com/securityphoenix/cisco-CVE-2023-20198-tester POC Details
4 None https://github.com/emomeni/Simple-Ansible-for-CVE-2023-20198 POC Details
5 CVE-2023-20198 & 0Day Implant Scanner https://github.com/ZephrFish/CVE-2023-20198-Checker POC Details
6 Checker for CVE-2023-20198 , Not a full POC Just checks the implementation and detects if hex is in response or not https://github.com/JoyGhoshs/CVE-2023-20198 POC Details
7 CVE-2023-20198 PoC (!) https://github.com/Tounsi007/CVE-2023-20198 POC Details
8 This script can identify if Cisco IOS XE devices are vulnerable to CVE-2023-20198 https://github.com/alekos3/CVE_2023_20198_Detector POC Details
9 Ansible Playbook for CVE-2023-20198 https://github.com/ditekshen/ansible-cve-2023-20198 POC Details
10 None https://github.com/reket99/Cisco_CVE-2023-20198 POC Details
11 1vere$k POC on the CVE-2023-20198 https://github.com/iveresk/cve-2023-20198 POC Details
12 CISCO CVE POC SCRIPT https://github.com/sohaibeb/CVE-2023-20198 POC Details
13 Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273) https://github.com/fox-it/cisco-ios-xe-implant-detection POC Details
14 A PoC for CVE 2023-20198 https://github.com/Pushkarup/CVE-2023-20198 POC Details
15 This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273 https://github.com/Shadow0ps/CVE-2023-20198-Scanner POC Details
16 Check a target IP for CVE-2023-20198 https://github.com/kacem-expereo/CVE-2023-20198 POC Details
17 None https://github.com/mr-r3b00t/CVE-2023-20198-IOS-XE-Scanner POC Details
18 None https://github.com/ohlawd/CVE-2023-20198 POC Details
19 None https://github.com/IceBreakerCode/CVE-2023-20198 POC Details
20 An Exploitation script developed to exploit the CVE-2023-20198 Cisco zero day vulnerability on their IOS routers https://github.com/sanjai-AK47/CVE-2023-20198 POC Details
21 CVE-2023-20198 Exploit PoC https://github.com/smokeintheshell/CVE-2023-20198 POC Details
22 Check for and remediate conditions that make an IOS-XE device vulnerable to CVE-2023-20198 https://github.com/netbell/CVE-2023-20198-Fix POC Details
23 Cisco CVE-2023-20198 https://github.com/Vulnmachines/Cisco_CVE-2023-20198 POC Details
24 An Exploitation script developed to exploit the CVE-2023-20198 Cisco zero day vulnerability on their IOS routers https://github.com/RevoltSecurities/CVE-2023-20198 POC Details
25 CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands. https://github.com/W01fh4cker/CVE-2023-20198-RCE POC Details
26 None https://github.com/sanan2004/CVE-2023-20198 POC Details
27 🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker successfully bypassed authentication, gaining admin control over the device! Immediate containment was critical. Stay vigilant! 💻🔐 https://github.com/AhmedMansour93/Event-ID-193-Rule-Name-SOC231-Cisco-IOS-XE-Web-UI-ZeroDay-CVE-2023-20198- POC Details
28 CVE-2023-20198是思科IOS XE软件Web UI功能中的一个严重漏洞,允许未经身份验证的远程攻击者在受影响的系统上创建具有特权级别15的账户,从而完全控制设备。 https://github.com/XiaomingX/CVE-2023-20198-poc POC Details
29 CVE-2023-20198是思科IOS XE软件Web UI功能中的一个严重漏洞,允许未经身份验证的远程攻击者在受影响的系统上创建具有特权级别15的账户,从而完全控制设备。 https://github.com/XiaomingX/cve-2023-20198-poc POC Details
30 A go-exploit to scan for implanted Cisco IOS XE Systems cve-2023-20198, go-exploit https://github.com/unsightlyabol/cisco-ios-xe-implant-scanner POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-20198

请登录查看更多情报信息。

Vendor Advisories for CVE-2023-20198 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-20198

No comments yet


Leave a comment