Cyber Resilience

CVE-2023-20198

Cisco Ios Xe 16.12 – 16.12.10a

CISA KEVActive ExploitationEUVD Exploited
Published
16 October 2023
Modified
28 October 2025
KEV Added
16 October 2023
Patch / advisory
CVSS Score v3.1 10.0
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.99 99.9th percentile
Risk Priority 100 floored blend · peak EPSS

Summary

CVE-2023-20198 is a critical-severity Unprotected Alternate Channel (CWE-420) vulnerability in Cisco Ios Xe. Its CVSS base score is 10.0 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Fallback Channels (T1008); ranked in the top 0.1% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2023-20198 is a critical vulnerability in the web UI feature of Cisco IOS XE Software. It carries a CVSS score of 10.0 and is associated with CWE-420. The issue was identified during Cisco's investigation of active exploitation and is tracked under CSCwh87343 alongside a related flaw, CVE-2023-20273.

Remote attackers can exploit CVE-2023-20198 without authentication to obtain initial access to affected devices. They then issue privilege-15 commands to create a local user account, after which a second web UI component is leveraged with that account to escalate privileges to root and install an implant on the file system.

Cisco's security advisory details the provision of updated fixed releases and a Software Checker tool for identifying vulnerable instances. The vulnerability is also listed in CISA's Known Exploited Vulnerabilities catalog, confirming observed in-the-wild activity.

EPSS scores have reached a peak of 0.9556 with a current value of 0.9401, reflecting sustained and widespread exploitation interest following disclosure.

EU & UK References

Vulnerability Data

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that…

more

the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

CWE(s)
KEV Date Added
16 October 2023

Related Threats

MITRE ATT&CK Enterprise Techniques

T1008 Fallback Channels Command And Control
Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.
T1048 Exfiltration Over Alternative Protocol Exfiltration
Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol Exfiltration
Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.
T1571 Non-Standard Port Command And Control
Adversaries may communicate using a protocol and port pairing that are typically not associated.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2025-54309Shared CWE-420both on KEV
CVE-2018-0172Same product: Cisco Ios Xeboth on KEV
CVE-2018-0175Same product: Cisco Ios Xeboth on KEV
CVE-2018-0174Same product: Cisco Ios Xeboth on KEV
CVE-2018-0158Same product: Cisco Ios Xeboth on KEV
CVE-2018-0155Same product: Cisco Ios Xeboth on KEV
CVE-2018-0167Same product: Cisco Ios Xeboth on KEV
CVE-2018-0173Same product: Cisco Ios Xeboth on KEV
CVE-2018-0151Same product: Cisco Ios Xeboth on KEV
CVE-2017-6663Same product: Cisco Ios Xeboth on KEV

Affected Assets

rockwellautomation
allen-bradley stratix 5200 firmware
≤ 17.12.02
rockwellautomation
allen-bradley stratix 5800 firmware
≤ 17.12.02
cisco
ios xe
16.12 — 16.12.10a · 17.3 — 17.3.8a · 17.6 — 17.6.6a

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-420

Usage restrictions and authorization for remote access protect against unprotected alternate channels.

addresses: CWE-420

TSCM surveys detect and neutralize unprotected alternate channels introduced by surveillance equipment or modifications.

addresses: CWE-420

Removes or disables unprotected alternate I/O channels that could otherwise be used to bypass primary controls.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.DS-02 mostly match
prevents

Protecting all data-in-transit directly mitigates unequal channel protection though the control addresses broader transit scenarios.

PR.IR-01 mostly match
prevents

Network protection from unauthorized access inherently requires securing every channel, not just primaries.

DE.CM-01 partial match
prevents

Network monitoring can surface use of unprotected alternate channels but does not prevent the design flaw.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

Access restrictions may cover primary paths but leave alternate channels unprotected unless explicitly extended.

prevents

Secure authentication applies to primary channels but does not ensure alternate channels receive the same strength.

mitigates

Network security controls ensure all channels receive equivalent protection, directly addressing unprotected alternate channels.

prevents

Security of network services requires consistent protection across all service channels, mitigating alternate-channel weaknesses.

mitigates

Network segregation can reduce exposure of alternate channels but does not guarantee equivalent protection levels.

mitigates

Cryptography can protect alternate channels but does not address the policy of applying equal protection across channels.

References