Actively exploited vulnerability
Cisco IOS XE Web UI: code execution flaw under attack
CVE-2023-20273 · Cisco IOS XE Web UI Command Injection Vulnerability
What is affected
Cisco IOS XE Web UI is found on ordinary personal computers and phones, so this is not only a problem for companies. If you use it and have not updated since the fix was released, you are exposed.
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.
What an attacker can do
This is a code execution flaw. It lets an attacker run their own commands or programs on the affected system. In practice that usually means taking it over: installing malware, stealing data or using it to reach other devices on the same network.
- How it is reached
- Over the internet or network
- Access the attacker needs
- An administrator account
- Does the victim have to do something?
- No, works without the victim doing anything
What to do
- Update Cisco IOS XE Web UI now. Open the update or "About" screen, install whatever is offered and restart the app or device, because the fix is not active until you do.
- Turn on automatic updates so the next fix arrives without you having to look for it.
- If your device is too old to receive this update, stop using the affected app for anything sensitive and plan a replacement.
Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.
Vendor advisories and fixes
- sec.cloudapps.cisco.comsec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui
How urgent is it
CISA added this vulnerability to its Known Exploited Vulnerabilities catalogue on October 23, 2023, which means there is reliable evidence of attacks in the wild. US federal agencies must fix it by October 27, 2023, a deadline that has already passed. That deadline does not bind anyone else, but it shows how seriously the agency rates it.
The EPSS model estimates a 90% probability that this flaw will be exploited somewhere in the next 30 days. That is higher than 99.8% of all scored vulnerabilities.
Its CVSS severity score is 7.2 out of 10 (high), as recorded in the US National Vulnerability Database.
Technical description
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.