LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2023-20273

CVE-2023-20273

Cisco IOS XE Web UI Command Injection Vulnerability

CVSS 7.2 · HIGH ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2023-10-23. Federal remediation due 2023-10-27.
Required action: Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.

Summary

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

CVSS 3.1 breakdown

Base score7.2 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredHIGH
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Cisco ios xeCisco catalyst 3650Cisco catalyst 3650-12x48fd-eCisco catalyst 3650-12x48fd-lCisco catalyst 3650-12x48fd-sCisco catalyst 3650-12x48uqCisco catalyst 3650-12x48uq-eCisco catalyst 3650-12x48uq-lCisco catalyst 3650-12x48uq-sCisco catalyst 3650-12x48urCisco catalyst 3650-12x48ur-eCisco catalyst 3650-12x48ur-lCisco catalyst 3650-12x48ur-sCisco catalyst 3650-12x48uzCisco catalyst 3650-12x48uz-eCisco catalyst 3650-12x48uz-lCisco catalyst 3650-12x48uz-sCisco catalyst 3650-24pdCisco catalyst 3650-24pd-eCisco catalyst 3650-24pd-l
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

Our coverage

References

Data: NIST NVD + CISA KEV. NVD last modified 2025-10-28. Always verify against the vendor advisory before acting.

Scroll to Top