A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2023-20198

Cisco IOS XE Web UI Privilege Escalation Vulnerability

Published
2023-10-16
Modified
2026-07-31
Sources
cisa-kev

Summary

Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.