Fix it, then report whether you were already breached — the duty added on Cisco IOS XE
For the privilege escalation flaw in the Cisco IOS XE web interface, CISA required agencies not only to apply mitigations but to determine whether they had been compromised and report any positive findings immediately.
Key facts
- CVE IDCVE-2023-20198
- Affected (vendor / product)Cisco IOS XE Web UI
- CWECWE-420
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2023-10-20 (U.S. federal civilian agencies, BOD 22-01)
Key points
- CVE-2023-20198 is a privilege escalation vulnerability in the Cisco IOS XE web user interface.
- Someone remote and unauthenticated may be able to set up an account carrying privilege level 15 and from there take the device over.
- The required action includes verifying compliance with binding operational directive BOD 23-02 and applying mitigations per vendor instructions.
- For instances reachable from the internet or an untrusted network it also requires working out whether the system might already have been broken into, and telling CISA at once if it was.
- Listed 16 October 2023 with a due date of 20 October, a window of four days; among the 1,579 entries without an article this site holds as of 2026-09-05, the instruction takes forty forms.
1Work that comes after the fix
The three entries so far asked for the hole to be closed. This one does not stop there. Once it is closed, the instruction asks agencies to find out whether someone was already inside, and to say so if they were.
2Four requirements
- 1VerifyConfirm that instances of the Cisco IOS XE web interface comply with binding operational directive BOD 23-02
- 2ApplyApply mitigations per vendor instructions
- 3DetermineFor instances exposed to the internet or untrusted networks, follow vendor instructions to determine whether the system may have been compromised
- 4ReportReport any positive findings to CISA immediately
That determining and reporting appear in the instruction at all is what marks this entry. Remediation ends inside an organization; reporting travels outward. The instruction reaches past one agency's own devices toward a picture of the government as a whole.
3Why ask for a report
As the description states, this flaw lets an attacker create an account at privilege level 15. That account survives the closing of the hole. Shutting the door and removing whoever is already inside are separate jobs. The requirement to determine exists to cover the difference.
4Four days
Of the forty forms the instruction takes, very few write in a duty to report. The next article takes up an entry where applying the update was not enough and every session had to be killed as well.
Why it matters
Closing a hole and removing whoever is already through it are separate jobs. Where a flaw lets an attacker create an account at privilege level 15, the account outlives the fix, so the instruction adds a determination of whether compromise occurred. Requiring positive findings to be reported extends the instruction past one organization devices toward a view of the whole.
FAQ
Why is a report required?
Which devices must be checked?
What is BOD 23-02?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).