CVE-2023-20198

Vulnerability updated a month ago (2024-11-29T13:51:30.892Z)
Download STIX
Preview STIX
CVE-2023-20198 is a significant software vulnerability discovered in the Web User Interface (Web UI) feature of Cisco IOS XE software. This flaw, identified by Cisco, has been actively exploited when exposed to the internet or untrusted networks. The exploitation of this zero-day vulnerability has led to the creation of unauthorized admin accounts and installation of implants on Cisco IOS XE devices, compromising their security. Furthermore, threat actors have used this critical weakness to compromise thousands of Cisco IOS XE devices, as warned by the security firm VulnCheck. Throughout the past year, several compromises were initiated through poorly secured Windows RDP implementations and compromised credentials. However, towards the end of the year, many network breaches occurred by exploiting CVE-2023-20198 in devices running Cisco Systems’ IOS XE operating system. This situation was part of a broader context where top zero-day flaws came from vendors like Citrix and Cisco, involving code injection bugs, privilege escalation, and buffer overflow vulnerabilities. In response to these security threats, Cisco took action to address the vulnerabilities. In October, two zero-day vulnerabilities (CVE-2023-20198 and CVE-2023-20273) were patched after they were exploited to compromise over 50,000 IOS XE devices within a single week. Following these events, Cisco released a security advisory and update to rectify the vulnerability (CVE-2023-20198) affecting IOS XE Software Web UI, thereby reducing the risk of future device control takeovers by cyber threat actors.
Description last updated: 2024-11-15T16:10:17.389Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Cisco
Ios
Vulnerability
Exploit
CISA
Zero Day
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Vulnerabilities
To see the evidence that has resulted in these vulnerability associations, create a free account
Alias DescriptionAssociation TypeVotes
The CVE-2023-20273 Vulnerability is associated with CVE-2023-20198. CVE-2023-20273 is a high-severity zero-day vulnerability disclosed by Cisco on October 21, 2023. This flaw in software design or implementation was actively exploited to deploy malicious implants on IOS XE devices. The exploitation of this vulnerability was discovered during the investigation of anois related to
2
Source Document References
Information about the CVE-2023-20198 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
a month ago
CISA
a month ago
Securityaffairs
5 months ago
Securityaffairs
5 months ago
Securityaffairs
5 months ago
Securityaffairs
5 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
7 months ago
Securityaffairs
8 months ago
Securityaffairs
8 months ago
Securityaffairs
9 months ago
Securityaffairs
9 months ago
Securityaffairs
9 months ago
Securityaffairs
9 months ago
Securityaffairs
9 months ago
Securityaffairs
10 months ago