# Cisco IOS XE web UI flaw exploited

Published: 2023-11-01 · Severity: critical · Sectors: telecommunications, government-national, technology
Canonical: https://vorant.io/reports/0a9bd2b4-9fe0-553a-bc47-07dd9a13d26f/cisco-ios-xe-web-ui-flaw-exploited

> A privilege-escalation vulnerability in Cisco IOS XE's web UI is being actively exploited to create rogue admin accounts and take over devices.

IPA (Japan's Information-technology Promotion Agency) issued an alert regarding a privilege escalation vulnerability in Cisco IOS XE, the operating system used across Cisco's networking equipment. The flaw allows a remote, unauthenticated attacker to create a highest-privilege account on the affected system, potentially granting full control of the device.

The advisory states that exploitation of this vulnerability has already been observed in the wild, prompting IPA to urge organizations to apply vendor-provided fixes, follow recommended mitigations, and investigate systems for signs of compromise as soon as possible. Cisco has published guidance on detecting exploitation and post-compromise indicators, which IPA directs readers to consult directly. The alert was updated on November 2, 2023, to expand the list of affected systems and add patched version information.

## Mentioned in this report

- Vulnerabilities: CVE-2023-20198 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/alert20231023-1.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0a9bd2b4-9fe0-553a-bc47-07dd9a13d26f/cisco-ios-xe-web-ui-flaw-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
