CVE-2023-20198
Cisco IOS XE Web UI Privilege Escalation Vulnerability
⚠ KEVEPSS 99.6%
Description
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.
How to fix CVE-2023-20198
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2023-20198 being exploited?
Yes — CVE-2023-20198 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.