CVE-2023-20273
Cisco IOS XE Web UI Command Injection Vulnerability
Description
CVE-2023-20273 is an OS command injection vulnerability in the web UI of Cisco IOS XE Software that allows an authenticated remote attacker to inject and execute commands with root privileges on the underlying operating system. The vulnerability arises from insufficient input validation in the web UI, enabling attackers to send crafted input that results in privileged command execution. This command injection flaw affects Cisco IOS XE devices and carries a HIGH severity rating. CISA has added CVE-2023-20273 to the Known Exploited Vulnerabilities catalog, and the EPSS score of 92.4% indicates a very high probability of active exploitation across Cisco IOS XE deployments.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| cisco | ios xe | 16.1.1; 16.1.2; 16.1.3; 16.2.1; 16.2.2; 16.3.1a; 16.3.2; 16.3.3; 16.3.4; 16.3.5; 16.3.5b; 16.3.6; 16.3.7; 16.3.8; 16.3.9; 16.3.10; 16.3.11; 16.4.1; 16.4.2; 16.4.3; 16.5.1; 16.5.1a; 16.5.1b; 16.5.2; 16.5.3; 16.6.1; 16.6.2; 16.6.3; 16.6.4; 16.6.4a; 16.6.5; 16.6.5a; 16.6.6; 16.6.7; 16.6.8; 16.6.9; 16.6.10; 16.7.1; 16.7.1a; 16.7.1b; 16.7.2; 16.7.3; 16.7.4; 16.8.1; 16.8.1a; 16.8.1b; 16.8.1c; 16.8.1d; 16.8.1e; 16.8.1s; 16.8.2; 16.8.3; 16.9.1; 16.9.1a; 16.9.1b; 16.9.1s; 16.9.2; 16.9.3; 16.9.3a; 16.9.4; 16.9.5; 16.9.5f; 16.9.6; 16.9.7; 16.9.8; 16.10.1; 16.10.1a; 16.10.1b; 16.10.1c; 16.10.1d; 16.10.1e; 16.10.1f; 16.10.1g; 16.10.1s; 16.10.2; 16.10.3; 16.11.1; 16.11.1a; 16.11.1b; 16.11.1s; 16.11.2; 16.12.1; 16.12.1a; 16.12.1c; 16.12.1s; 16.12.1t; 16.12.1w; 16.12.1x; 16.12.1y; 16.12.1z1; 16.12.1z2; 16.12.2; 16.12.2a; 16.12.2s; 16.12.3; 16.12.3a; 16.12.3s; 16.12.4; 16.12.4a; 16.12.5; 16.12.5a; 16.12.5b; 16.12.6; 16.12.6a; 16.12.7; 16.12.8; 16.12.9; 16.12.10; 17.1.1; 17.1.1a; 17.1.1s; 17.1.1t; 17.1.3; 17.2.1; 17.2.1a; 17.2.1r; 17.2.1v; 17.2.2; 17.2.3; 17.3.1; 17.3.1a; 17.3.1w; 17.3.1x; 17.3.1z; 17.3.2; 17.3.2a; 17.3.3; 17.3.4; 17.3.4a; 17.3.4b; 17.3.4c; 17.3.5; 17.3.5a; 17.3.5b; 17.3.6; 17.3.7; 17.3.8; 17.4.1; 17.4.1a; 17.4.1b; 17.4.2; 17.4.2a; 17.5.1; 17.5.1a; 17.5.1b; 17.5.1c; 17.6.1; 17.6.1a; 17.6.1w; 17.6.1x; 17.6.1y; 17.6.1z; 17.6.1z1; 17.6.2; 17.6.3; 17.6.3a; 17.6.4; 17.6.5; 17.6.6; 17.7.1; 17.7.1a; 17.7.1b; 17.7.2; 17.8.1; 17.8.1a; 17.9.1; 17.9.1a; 17.9.1w; 17.9.1x; 17.9.1x1; 17.9.1y; 17.9.1y1; 17.9.2; 17.9.2a; 17.9.3; 17.9.3a; 17.9.4; 17.10.1; 17.10.1a; 17.10.1b; 17.11.1; 17.11.1a; 17.11.99sw; 17.12.1; 17.12.1a; >= 17.3, < 17.3.8a; >= 17.6, < 17.6.6a; >= 17.9, < 17.9.4a; >= 16.12, < 16.12.10a |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
References
Weakness Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
The Cisco IOS XE web UI fails to properly neutralize special elements in user-supplied input before passing it to operating system commands. This OS command injection weakness allows an authenticated attacker to craft malicious input through the web interface that breaks out of the intended command context and executes arbitrary commands with root-level privileges on the IOS XE device.
Learn more: CWE-78 — OS Command Injection
Impact Analysis
CVE-2023-20273 is rated HIGH severity with a CVSS v3.1 score of 7.2, reflecting serious risk to Cisco IOS XE infrastructure. The vulnerability is remotely exploitable without physical access and requires low attack complexity, meaning no special conditions are needed beyond network access to the web UI. While high privileges are required to exploit this flaw, meaning the attacker must have administrative-level access to the web UI, no user interaction is needed to trigger the exploit. Confidentiality (High): an attacker with root command execution can access all data on the device, including routing tables, VPN configurations, credentials, and network traffic metadata. Integrity (High): root-level access enables modification of device configurations, installation of persistent backdoors, and manipulation of network routing and security policies. Availability (High): command execution with root privileges can disrupt or completely shut down network services running on the IOS XE device. The EPSS score of 92.4% (99th percentile) underscores the near-certain likelihood of exploitation, making immediate remediation critical for organizations running Cisco IOS XE with the web UI enabled.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2023-20273 in the wild by adding it to the Known Exploited Vulnerabilities catalog with an accelerated remediation deadline of October 27, 2023, reflecting the urgency of the threat. The EPSS score of 92.4% (99th percentile) indicates near-certain exploitation activity across the internet. While no public exploit code tagged as "Exploit" appears in the NVD references, the active exploitation confirmed by CISA and the extremely high EPSS score demonstrate that threat actors possess and are using working exploits against Cisco IOS XE web UI deployments. This vulnerability is particularly dangerous when chained with other Cisco IOS XE web UI vulnerabilities that may provide the initial authenticated access required for exploitation.
Remediation
- Apply vendor mitigations immediately as directed by CISA: "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable." Consult the Cisco security advisory for specific patched IOS XE software versions and upgrade guidance.
- Disable the Cisco IOS XE web UI if it is not required for device management. Use the commands
no ip http serverandno ip http secure-serverto disable the HTTP and HTTPS web UI services entirely, eliminating the attack surface for this vulnerability. - Restrict access to the IOS XE web UI by implementing access control lists (ACLs) that limit HTTP/HTTPS management access to trusted management networks and specific administrator IP addresses only. Ensure the web UI is not accessible from the internet or untrusted network segments.
- Monitor IOS XE devices for indicators of compromise by reviewing system logs for unexpected command execution, checking for unauthorized user accounts or privilege escalations, inspecting the device configuration for unauthorized changes, and looking for implants or web shells that may have been installed through root-level command execution.
- Implement network-level protections including intrusion detection/prevention rules for Cisco IOS XE web UI exploitation attempts, network segmentation to isolate management plane traffic, and centralized logging with alerting on anomalous administrative activity on IOS XE devices.
Technical Details
CVE-2023-20273 is an OS command injection vulnerability in the web UI feature of Cisco IOS XE Software, classified under CWE-78 (Improper Neutralization of Special Elements used in an OS Command). The root cause is insufficient input validation in the web UI, where user-supplied data is incorporated into operating system commands without adequate sanitization of special characters that could alter command structure. As reflected in the CVSS vector (AV:N/AC:L/PR:H/UI:N/S:U), the attack is network-accessible with low complexity but requires high privileges, meaning the attacker needs administrative-level authentication to the web UI before they can inject commands. The unchanged scope (S:U) indicates that while the impact is confined to the IOS XE device itself, the attacker gains root-level command execution (C:H/I:H/A:H), which represents complete compromise of the device. The high privilege requirement somewhat mitigates the risk, but in practice, threat actors may obtain the necessary credentials through credential theft, brute force, or by chaining this vulnerability with authentication bypass flaws in the same IOS XE web UI.
Frequently Asked Questions
Is CVE-2023-20273 being actively exploited?
Yes, CVE-2023-20273 is being actively exploited in the wild. CISA has added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of October 27, 2023. The EPSS score of 92.4% places it at the 99th percentile, confirming widespread exploitation activity targeting Cisco IOS XE devices.
What products are affected by CVE-2023-20273?
CVE-2023-20273 affects Cisco IOS XE Software with the web UI feature enabled. This includes a wide range of Cisco networking devices running IOS XE, such as routers, switches, and wireless controllers that expose the web-based management interface.
How do I fix CVE-2023-20273?
Apply the patched IOS XE software version referenced in Cisco's security advisory cisco-sa-iosxe-webui-privesc-j22SaA4z. As an immediate mitigation, disable the IOS XE web UI using the no ip http server and no ip http secure-server commands if the web interface is not required, or restrict access to trusted management networks only.
How severe is CVE-2023-20273?
CVE-2023-20273 is rated HIGH severity with a CVSS v3.1 score of 7.2 out of 10. While it requires high privileges to exploit, successful exploitation grants root-level command execution on the device. The EPSS score at the 99th percentile and confirmed active exploitation by CISA underscore the critical real-world risk.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.