Exploited Known exploited (KEV) CVE-2023-20198

Fix it, then report whether you were already breached — the duty added on Cisco IOS XE

Cisco IOS XE Web UI Added to KEV Oct 16, 2023 Federal remediation due 2023-10-20

For the privilege escalation flaw in the Cisco IOS XE web interface, CISA required agencies not only to apply mitigations but to determine whether they had been compromised and report any positive findings immediately.

Key facts

  • CVE IDCVE-2023-20198
  • Affected (vendor / product)Cisco IOS XE Web UI
  • CWECWE-420
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2023-10-20 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • CVE-2023-20198 is a privilege escalation vulnerability in the Cisco IOS XE web user interface.
  • Someone remote and unauthenticated may be able to set up an account carrying privilege level 15 and from there take the device over.
  • The required action includes verifying compliance with binding operational directive BOD 23-02 and applying mitigations per vendor instructions.
  • For instances reachable from the internet or an untrusted network it also requires working out whether the system might already have been broken into, and telling CISA at once if it was.
  • Listed 16 October 2023 with a due date of 20 October, a window of four days; among the 1,579 entries without an article this site holds as of 2026-09-05, the instruction takes forty forms.

1Work that comes after the fix

The three entries so far asked for the hole to be closed. This one does not stop there. Once it is closed, the instruction asks agencies to find out whether someone was already inside, and to say so if they were.

2Four requirements

  1. 1VerifyConfirm that instances of the Cisco IOS XE web interface comply with binding operational directive BOD 23-02
  2. 2ApplyApply mitigations per vendor instructions
  3. 3DetermineFor instances exposed to the internet or untrusted networks, follow vendor instructions to determine whether the system may have been compromised
  4. 4ReportReport any positive findings to CISA immediately

That determining and reporting appear in the instruction at all is what marks this entry. Remediation ends inside an organization; reporting travels outward. The instruction reaches past one agency's own devices toward a picture of the government as a whole.

3Why ask for a report

The aspectA typical entryThis entry, Cisco IOS XE
What is askedClose the vulnerabilityClose it, determine whether compromised, and report if so
Where it endsInside the organizationAt a report to CISA
Situation assumedExploitation may followSomeone may already be inside
What an attacker gainsAn account at privilege level 15, and control of the device

As the description states, this flaw lets an attacker create an account at privilege level 15. That account survives the closing of the hole. Shutting the door and removing whoever is already inside are separate jobs. The requirement to determine exists to cover the difference.

4Four days

Of the 1,695 records this site holds as of 2026-09-05, those without an article1,579The required action takes forty forms
Of those, instructions going as far as determination and reportingA handfulThe twenty-two individual forms appear one to four times each
The window hereFour daysListed 16 October 2023, due 20 October 2023

Of the forty forms the instruction takes, very few write in a duty to report. The next article takes up an entry where applying the update was not enough and every session had to be killed as well.

Why it matters

Closing a hole and removing whoever is already through it are separate jobs. Where a flaw lets an attacker create an account at privilege level 15, the account outlives the fix, so the instruction adds a determination of whether compromise occurred. Requiring positive findings to be reported extends the instruction past one organization devices toward a view of the whole.

FAQ

Why is a report required?
Because the flaw lets an attacker create an account at privilege level 15, and that account survives after the vulnerability itself is closed.
Which devices must be checked?
Instances of the Cisco IOS XE web user interface exposed to the internet or to untrusted networks.
What is BOD 23-02?
The binding operational directive the instruction requires compliance with, verification of which forms part of the required action.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#CISA#United States#Cybersecurity
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.