Cisco IOS XE Web UI (CVE-2023-20198)
CVE-2023-20198CWE-420OWASP A05:2021CVSS 10.0Updated October 1, 20262 min read
CVE-2023-20198 is a vulnerability in the Cisco IOS XE web management interface that let anyone who could reach it create an account at the highest privilege level. It scores 10.0. Within days tens of thousands of devices carried an implant, planted by exploiting a second bug, CVE-2023-20273. The real cause was not only the bug but that a management interface was facing the internet at all.
- Affected
- Cisco IOS XE with the HTTP or HTTPS server feature enabled and reachable from an untrusted network
- Patched in
- The fixed releases from the Cisco advisory, which also fix CVE-2023-20273; as an interim step, disable the HTTP and HTTPS server
- Actively exploited
- yes
In October 2023 it turned out that attackers were creating accounts on Cisco routers and switches at scale. Cisco Talos later traced the first activity back to 18 September; Cisco’s support centre (TAC) received the first case on 28 September. To create those accounts the attackers did not have to guess a password or chain a vulnerability: the management interface did it for them. Planting their implant did take a second flaw.
What is CVE-2023-20198
IOS XE has a web interface for administration. By constructing a request in a particular way, an unauthenticated visitor could create a local account at the highest privilege level. From that point on they were an administrator of the device.
In practice the attackers logged in with that account and then exploited a second flaw in the same web interface, CVE-2023-20273 (CVSS 7.2), to escalate to root and write an implant to the file system. Through it they could run commands on the device. The implant itself was not persistent: a reboot removed it. The rogue local accounts did survive a reboot, and with them the attacker’s administrator access.
Why this is mostly a lesson about exposure
The bug was serious, but what created the scale was something else: tens of thousands of devices had their management interface on the open internet. A management interface belongs on a management network, not on the whole world. That is exactly what security misconfiguration describes.
Had the interface only been reachable internally, the same vulnerability would have been a problem for whoever was already inside, not for anyone with a connection.
Why it is still relevant
This is not a closed chapter. In August 2025 CISA, the NSA, the FBI and partner agencies from twelve other countries, the Netherlands and Germany among them, listed CVE-2023-20198 and CVE-2023-20273 among the vulnerabilities that Chinese state-sponsored actors use to compromise networks worldwide. That activity overlaps with what the security industry calls Salt Typhoon. In late October 2025 the Australian Signals Directorate (ASD) reported that more than 150 devices in Australia still carried the implant, now known as BADCANDY. A reboot clears it, but a device that is not patched can simply be infected again.
What to do now
- Disable the HTTP and HTTPS server feature on devices that do not need it, and otherwise restrict it to a management network.
- Move the devices to a supported IOS XE release that contains the fixes from the Cisco advisory. They close both vulnerabilities.
- Review the configuration for accounts nobody can account for, and remove them after investigating rather than before. A reboot removes the implant, not those accounts.
- Inventory which of your organisation’s management interfaces are reachable from the internet. Exposure like this is usually the first finding in a penetration test.
Sources
- Cisco: Multiple Vulnerabilities in Cisco IOS XE Software Web UI Featuresec.cloudapps.cisco.com
- NVD: CVE-2023-20198nvd.nist.gov
- Cisco Talos: Active exploitation of Cisco IOS XE Software Web Management UIblog.talosintelligence.com
- CISA: Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide (AA25-239A)cisa.gov
Frequently asked questions
What exactly is the flaw here?
The web interface accepted a request that did not pass the normal access control and created an account at the highest privilege level on the strength of it. No password was needed.
Why do you call this a misconfiguration?
The vulnerability was in the software, but the attack surface existed because a management interface was reachable from the internet. Cisco has advised against that for years.
How do I tell whether a device was hit?
Check for local accounts you did not create, such as cisco_tac_admin or cisco_support, and for unknown file installations in the logs. Cisco and Talos published a request that reveals the implant, but a new implant version deployed from around 20 October 2023 evaded that first check; Talos published an updated check on 23 October. A negative result says nothing about rogue accounts: a reboot removes the implant, not the accounts.
Related articles
- CVEsCWE-77A03:2021PAN-OS GlobalProtect (CVE-2024-3400)CVE-2024-3400 explained: how a command injection in the GlobalProtect gateway or portal of PAN-OS handed attackers root on the firewall itself.
- VulnerabilitiesCWE-287A07:2021Broken authenticationBroken authentication explained: how attackers take over accounts through brute force, leaked passwords and predictable session tokens, and how to stop them.
- VulnerabilitiesCWE-94A03:2021Remote code execution (RCE)Remote code execution (RCE) explained: how attackers run their own commands or code on your server through unvalidated input, and how to prevent it.
- VulnerabilitiesCWE-16A05:2021Security misconfigurationSecurity misconfiguration explained: how default passwords, debug modes and open cloud buckets let attackers in, and how to harden your systems.