CVE-2023-20273: Cisco IOS XE Web UI Command Injection Vulnerability
Status: confirmed exploited in the wild
CVE-2023-20273 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2023-10-23. Inclusion in KEV is not a severity prediction. It means CISA has reliable evidence that the vulnerability has actually been exploited against real targets, which is a stronger signal than a CVSS score on its own.
| Field | Value |
|---|---|
| CVE | CVE-2023-20273 |
| Vendor | Cisco |
| Product | Cisco IOS XE Web UI |
| Added to KEV | 2023-10-23 |
| Federal due date | 2023-10-27 |
| Ransomware campaign use | Unknown |
What the vulnerability is
Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.
Weakness classification
CISA classifies this entry under:
Required action
CISA's stated required action for this entry:
Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.
Ransomware context
CISA lists ransomware campaign use for this entry as "Unknown". That is an absence of confirmation rather than evidence it has not been used, so it should not be read as lowering priority.
Federal remediation deadline
Under CISA Binding Operational Directive 22-01, U.S. federal civilian executive branch agencies were required to remediate this vulnerability by 2023-10-27. The directive does not bind private organisations, but the due date is a useful external signal: CISA sets shorter windows for what it assesses as higher risk.
Why KEV membership changes prioritisation
Most vulnerability backlogs are too large to clear, so the practical question is ordering rather than coverage. KEV is useful for that because it is evidence-based: an entry is on the list because exploitation was observed, not because a scoring formula predicted it might be.
A defensible triage rule used widely is to treat KEV membership as a promotion signal that overrides CVSS ranking, on the basis that a confirmed-exploited medium-severity issue generally warrants attention ahead of a theoretical critical one.
Determining whether you are affected
- Establish whether Cisco Cisco IOS XE Web UI is present anywhere in your estate, including indirectly and in systems not under active management.
- Identify the deployed versions and compare against the vendor advisory linked below.
- Apply the required action above, then confirm the change took effect rather than assuming it did.
Step one is where this usually fails. Several of the most costly incidents on record, including Code Red and Log4Shell, turned on organisations being unable to answer whether affected software was present at all.
How Safeguard helps
Safeguard's vulnerability management enriches findings with KEV and EPSS data, so an entry like this one surfaces as confirmed-exploited rather than sitting undifferentiated in a ranked list.
Sources
- CISA KEV catalog (version 2026.09.16): https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- NVD record for CVE-2023-20273: https://nvd.nist.gov/vuln/detail/CVE-2023-20273
- Vendor and advisory references: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z , https://nvd.nist.gov/vuln/detail/CVE-2023-20273
Catalog data retrieved from CISA KEV version 2026.09.16. Verify against the live catalog before relying on dates for compliance purposes.