CVE-2023-20273
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- October 27, 2022
- Published Date
- October 24, 2023
- Last Updated
- October 23, 2024
- Vendor
- Cisco
- Product
- Cisco IOS XE Software
- Description
- A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
- Tags
- Exploitation
- Active
- Technical Impact
- Total
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
SSVC Information
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2023-10-23 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/misc/cisco_ios_xe_rce.rb | 2025-04-29 11:01:18 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
cisco_ios_xe_rce
Type: metasploit • Created: Unknown
smokeintheshell/CVE-2023-20273
Type: github • Created: 2023-12-09 07:25:43 UTC • Stars: 9
Timeline
-
CVE ID Reserved
-
Added to KEVIntel
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Detected by Metasploit