CVE-2023-20273
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- October 27, 2022
- Published Date
- October 24, 2023
- Last Updated
- October 23, 2024
- Vendor
- Cisco
- Product
- Cisco IOS XE Software
- Description
- A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
CVSS Scores
CVSS v3.1
7.2 - HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- Active
- Technical Impact
- Total
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2023-10-23 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/misc/cisco_ios_xe_rce.rb | 2025-04-29 11:01:18 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
cisco_ios_xe_rce
Type: metasploit • Created: Unknown
Metasploit module for CVE-2023-20273
smokeintheshell/CVE-2023-20273
Type: github • Created: 2023-12-09 07:25:43 UTC • Stars: 9
CVE-2023-20273 Exploit PoC