Vulnerability intelligence
Products
Cisco · Stackable access/aggregation switch

Cisco Catalyst 9300

Platform: Cisco IOS XE
cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:*
Exposure

Critical. Web UI zero-days (CVE-2023-20198 + 20273, BadCandy) and Smart Install (CVE-2018-0171) both apply; Salt Typhoon activity.

Applicable CVEs
8
On CISA KEV
4
Threat actors
3
Urgency
Critical

Vulnerabilities

CVESeverityEPSSKEVExploitsActorsSource
CVE-2023-20198Critical · 10.0
100%
KEV352Curated
CVE-2018-0171Critical · 9.8
100%
KEV12Curated
CVE-2023-20273High · 7.2
90%
KEV12Curated
CVE-2025-20311High · 7.4
<1%
Curated
CVE-2023-20082Medium · 6.1
<1%
Curated

Threat actor activity

Salt Typhoon
Threat actor · China (state)
Curated

Living-off-the-land across telecom carriers; JumbledPath Go tool for packet capture and log erasure.

Static Tundra
Threat actor · Russia (state)
Curated

Smart Install exploitation of unpatched/EoL Cisco devices for intelligence collection (~250k exposed 4786).

BadCandy mass exploitation (unattributed)
Campaign · Unknown (Oct 2023)
Curated

Chained the IOS XE Web UI zero-days to implant the BadCandy Lua web shell on 40,000+ devices.

Indicators of compromise

No indicators of compromise recorded. Run AI enrichment to research IOCs.