What happened
Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.
Affected versions
IOS XE Web UI: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
PoC-in-GitHub · raystr-atearedteam/CVE-2023-20198-checker★ 0raystr-atearedteam2023-10-17CandidatePoC-in-GitHub · Atea-Redteam/CVE-2023-20198CVE-2023-20198 Checkscript★ 20Atea-Redteam2023-10-17CandidatePoC-in-GitHub · securityphoenix/cisco-CVE-2023-20198-testercisco-CVE-2023-20198-tester★ 1securityphoenix2023-10-17CandidatePoC-in-GitHub · emomeni/Simple-Ansible-for-CVE-2023-20198★ 1emomeni2023-10-17CandidatePoC-in-GitHub · ZephrFish/CVE-2023-20198-CheckerCVE-2023-20198 & 0Day Implant Scanner★ 33ZephrFish2023-10-17CandidatePoC-in-GitHub · JoyGhoshs/CVE-2023-20198Checker for CVE-2023-20198 , Not a full POC Just checks the implementation and detects if hex is in response or not★ 0JoyGhoshs2023-10-18CandidatePoC-in-GitHub · Tounsi007/CVE-2023-20198CVE-2023-20198 PoC (!)★ 11Tounsi0072023-10-18CandidatePoC-in-GitHub · alekos3/CVE_2023_20198_DetectorThis script can identify if Cisco IOS XE devices are vulnerable to CVE-2023-20198★ 2alekos32023-10-18CandidatePoC-in-GitHub · reket99/Cisco_CVE-2023-20198★ 0reket992023-10-20CandidatePoC-in-GitHub · iveresk/cve-2023-201981vere$k POC on the CVE-2023-20198★ 6iveresk2023-10-20CandidatePoC-in-GitHub · sohaibeb/CVE-2023-20198CISCO CVE POC SCRIPT★ 4sohaibeb2023-10-20CandidatePoC-in-GitHub · fox-it/cisco-ios-xe-implant-detectionCisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)★ 41fox-it2023-10-23CandidatePoC-in-GitHub · Pushkarup/CVE-2023-20198A PoC for CVE 2023-20198★ 8Pushkarup2023-10-23CandidatePoC-in-GitHub · Shadow0ps/CVE-2023-20198-ScannerThis is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273★ 33Shadow0ps2023-10-23CandidatePoC-in-GitHub · kacem-expereo/CVE-2023-20198Check a target IP for CVE-2023-20198★ 1kacem-expereo2023-10-24CandidatePoC-in-GitHub · mr-r3b00t/CVE-2023-20198-IOS-XE-Scanner★ 2mr-r3b00t2023-10-25CandidatePoC-in-GitHub · ohlawd/CVE-2023-20198★ 0ohlawd2023-10-25CandidatePoC-in-GitHub · IceBreakerCode/CVE-2023-20198★ 1IceBreakerCode2023-10-25CandidatePoC-in-GitHub · RevoltSecurities/CVE-2023-20198An Exploitation script developed to exploit the CVE-2023-20198 Cisco zero day vulnerability on their IOS routers★ 7RevoltSecurities2023-11-03CandidatePoC-in-GitHub · smokeintheshell/CVE-2023-20198CVE-2023-20198 Exploit PoC★ 66smokeintheshell2023-11-16CandidatePoC-in-GitHub · netbell/CVE-2023-20198-FixCheck for and remediate conditions that make an IOS-XE device vulnerable to CVE-2023-20198★ 0netbell2023-12-08CandidatePoC-in-GitHub · Vulnmachines/Cisco_CVE-2023-20198Cisco CVE-2023-20198★ 3Vulnmachines2023-12-11CandidatePoC-in-GitHub · W01fh4cker/CVE-2023-20198-RCECVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.★ 43W01fh4cker2024-04-25CandidatePoC-in-GitHub · sanan2004/CVE-2023-20198★ 0sanan20042024-08-26CandidatePoC-in-GitHub · AhmedMansour93/Event-ID-193-Rule-Name-SOC231-Cisco-IOS-XE-Web-UI-ZeroDay-CVE-2023-20198-🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker successfully bypassed authentication, gaining admin control over the device! Immediate containment was critical. Stay vigilant! 💻🔐★ 0AhmedMansour932024-09-13CandidatePoC-in-GitHub · djayaGit/cve-2023-20198-poc-ciscoCVE-2023-20198是思科IOS XE软件Web UI功能中的一个严重漏洞,允许未经身份验证的远程攻击者在受影响的系统上创建具有特权级别15的账户,从而完全控制设备。★ 1djayaGit2024-11-23CandidatePoC-in-GitHub · G4sul1n/Cisco-IOS-XE-CVE-2023-20198Exploit PoC for CVE-2023-20198★ 3G4sul1n2025-04-11CandidatePoC-in-GitHub · DOMINIC471/qub-network-security-cve-2023-20198Analysis, detection, and mitigation of CVE-2023-20198 exploitation in Cisco IOS XE – QUB CSC3064 Network Security Assessment★ 0DOMINIC4712025-05-15CandidatePoC-in-GitHub · Arshit01/CVE-2023-20198★ 0Arshit012025-06-09CandidatePoC-in-GitHub · Religan/CVE-2023-20198A cybersecurity case study analysing CVE-2023-20198 in Cisco IOS XE, covering vulnerability exploitation, mitigation strategies, secure software development frameworks, and patch management policies, with practical insights from a controlled lab environment★ 0Religan2025-12-15CandidatePoC-in-GitHub · Gill-Singh-A/CVE-2023-20198-ExploitProof-of-concept exploit for CVE-2023-20198, an authentication bypass vulnerability affecting Cisco IOS XE Web UI★ 0Gill-Singh-A2026-02-17CandidatePoC-in-GitHub · gustavorobertux/cisco-cve-2023-20198-checker★ 0gustavorobertux2026-03-08CandidatePoC-in-GitHub · telly251/forwardnetworksdemoDemo to remediate CVE-2023-20198 using forward networks and tines★ 0telly2512026-04-10CandidatePoC-in-GitHub · charlesjson/CVE-2023-20198★ 0charlesjson2026-06-25CandidatePoC-in-GitHub · abrahamsurf/CVE-2023-20198-Scanner★ 0abrahamsurf2026-07-08CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.