CVE-2023-20273: Cisco IOS XE Web UI Command Injection Vulnerability
Cisco Cisco IOS XE Web UI · in CISA KEV since 2023-10-23
- Kevscope API $5 pack $5 for 2,000 calls, never expires: patch-priority verdicts for up to 20 CVEs per call from today's KEV, EPSS, CVSS and SSVC data, by REST API or MCP. Pay by card, your API key is on screen the moment checkout ends; no account, no subscription.
- Exploited Vulnerabilities Brief: Weekly Edition $9/month: a fresh KEV + EPSS brief every Monday (PDF + CSVs): new exploited CVEs, what to patch first, upcoming CISA deadlines.
- Kevscope CVE priority API 200 free calls a day, $5 for 2,000 calls (no expiry), or $19/month for 10,000: returns a patch-priority verdict for up to 20 CVEs per call with the evidence (KEV, EPSS, CVSS, CISA SSVC), most urgent first, by API or MCP.
- Exploited Vulnerabilities Brief (September 2026) $15: this month's KEV additions ranked by EPSS, ransomware use and due date, as a one-off report.
- All Three Monday Briefs: Rates, Recalls + Exploited Vulns $25/month: all three weekly briefs (Treasury/BLS rates & macro, NHTSA recalls, CISA KEV/EPSS) for $25/month instead of $37.
What it is
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.
Required action (CISA)
Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.
| CWE | CWE-78 |
|---|---|
| CVSS vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| NVD published | 2023-10-25 (Analyzed) |
Original records: NVD · CISA KEV · JSON: /api/cve/CVE-2023-20273.json · all KEV CVEs
Get the full file: Exploited Vulnerabilities Brief – September 2026 ($29): this month's KEV additions ranked by EPSS, ransomware use and due date, ready to hand to a patch team. Checkout by Polar.