VDB
BDU%3A2023-06875
BDU%3A2023-06875
PUBLISHED
CVSS 10 CRITICAL
Уязвимость веб-интерфейса операционной системы Cisco IOS XE, позволяющая нарушителю повысить свои привилегии
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco IOS XE Software | 16.2.1, 16.1.3, 16.3.6 |
| Cisco Systems Inc. | Cisco IOS XE |
Timeline
- Oct 16, 2023 PoC Published
- Oct 17, 2023 CVE Published
- Oct 17, 2023 PoC Published
- Oct 17, 2023 PoC Published
- Oct 18, 2023 PoC Published
- Nov 8, 2023 PoC Published
- Nov 8, 2023 PoC Published
- Apr 26, 2024 CVE Updated
- Oct 14, 2024 PoC Published
- Oct 24, 2024 PoC Published
- Oct 25, 2024 PoC Published
- Oct 26, 2024 PoC Published
References
- https://systemip/webui/logoutconfirm.html?logon_hash=1" advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z advisory
- https://arstechnica.com/security/2023/10/actively-exploited-cisco-0-day-with-maximum-10-severity-gives-full-network-control/ url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-20198 url
- https://www.darkreading.com/vulnerabilities-threats/critical-unpatched-cisco-zero-day-bug-active-exploit url
- https://github.com/W01fh4cker/CVE-2023-20198-RCE url