CVE-2023-20273 is a critical command injection vulnerability in the web UI of Cisco IOS XE Software, allowing authenticated remote attackers to execute commands with root privileges due to insufficient input validation. This vulnerability carries a CVSS score of 7.2 (HIGH) and allows for full compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, with an EPSS score indicating high exploitability and multiple Metasploit modules available. The vulnerability has garnered significant community attention and media coverage, including links to state-sponsored threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.1.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.1.1:*:*:*:*:*:*:* | ||
16.1.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.1.2:*:*:*:*:*:*:* | ||
16.1.3CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.1.3:*:*:*:*:*:*:* | ||
16.2.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.2.1:*:*:*:*:*:*:* | ||
16.2.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.