Vulnerability intelligence
CVEs

CVE-2023-20273

High · 7.2KEVCWE-78Source: NVD

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

CVSS 3.1 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Published 10/25/2023

Threat actors

BadCandy mass exploitation (unattributed)
Campaign · Unknown (Oct 2023)
Curated

Chained the IOS XE Web UI zero-days to implant the BadCandy Lua web shell on 40,000+ devices.

Salt Typhoon
Threat actor · China (state)
Curated

Living-off-the-land across telecom carriers; JumbledPath Go tool for packet capture and log erasure.

Indicators of compromise

No indicators of compromise recorded. Run AI enrichment to research IOCs.
CISA KEV
Added 2023-10-23
Remediation due 2023-10-27
Ransomware use: Unknown
EPSS
90%

Probability of exploitation in the next 30 days.

Affected products
Public exploits / PoCs

Public repos, unvetted — presence is not exploit quality.