logo

CVE-2023-20198

ID: 4eefc839-5453-5fb7-8b0b-95667797ecb1

STIX ID: report--4eefc839-5453-5fb7-8b0b-95667797ecb1

Feed Name: Arctic Wolf Blog

Threat Score
90/100

Date Published: 2023-10-23

Date Updated: 2026-04-27

...
...

On October 16, 2023 Cisco disclosed CVE-2023-20198, an unpatched, actively exploited unauthenticated privilege-escalation vulnerability in the IOS XE Web UI (CVSS 10) that can create a privilege-level 15 account if the device's HTTP/HTTPS server feature is enabled; Cisco and Talos report exploitation since at least September and recommend restricting or disabling HTTP/HTTPS access as a temporary mitigation while patches are unavailable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.