CVE-2023-20198General(cisco / allen-bradley_stratix_5200)

MEDIUMCVSS 10.0 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch cisco allen-bradley_stratix_5200 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

5.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-10-20. Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.

Weakness type (CWE)
CWE-420

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • allen-bradley_stratix_5200
  • allen-bradley_stratix_5200_firmware
  • allen-bradley_stratix_5800
  • allen-bradley_stratix_5800_firmware

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 7d ago at 1 mentions (2026-01-27); latest day: 1
  • 8 total mentions across 8 days

Affected systems

Products
allen-bradley_stratix_5200allen-bradley_stratix_5200_firmwareallen-bradley_stratix_5800allen-bradley_stratix_5800_firmwareios_xe

1 version affected across 5 products

Deep dive

Activity timeline8 mentions / 8d
00111Mentions · 2026-01-27: 1Mentions · 2026-02-18: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-21: 1Mentions · 2026-04-07: 1Mentions · 2026-09-25: 1Active Exploitation · 2026-01-27: 1Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-01-27: 1Technical Details · 2026-02-18: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-21: 1Technical Details · 2026-04-07: 101-2702-1803-0603-0703-0803-2104-0709-25
Signal classification3 categories
General
450.0%
Active Exploitation
225.0%
Disclosure
225.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-271
Active Exploitation1
2026-02-181
General1
2026-03-061
General1
2026-03-071
General1
2026-03-081
General1
2026-03-211
Disclosure1
2026-04-071
Disclosure1
2026-09-251
Active Exploitation1
Full discourse8 posts
  • Shanaka Anslem Perera ⚡@shanaka86
    Active Exploitation

    You are touching the third rail. The documented kill chain … CVE-2023-20198: Perfect 10.0 severity score. Creates admin accounts remotely. No authentication needed. CVE-2023-20273: Elevates to root access. CVE-2018-0171: Patched SEVEN YEARS AGO. Still exploited because telecom infrastructure hadn’t updated since 2018. But here’s what should concern everyone: The malware, called Demodex, operates at KERNEL level. Below the operating system. It hooks into system calls to hide itself. When admins run diagnostics, the rootkit filters what they can see. You look for the infection. The infection decides what you find. It survives reboots. It survives reimaging. It survives patches. Cisco Talos documented one network compromised for 3+ years. CISA officially states they “cannot say with certainty” it’s been removed. You know what does remove it? Physical hardware replacement. That’s not a software problem. That’s an architecture problem. And you’re right to ask whether the architecture was the point all along.

    Post summary

    The post lists several CVEs with technical details, notes ongoing exploitation of one, cites a patch that is still not mitigating, and underscores kernel‑level malware persistence requiring hardware replacement for removal.

    160143684
    148.0K followersView on X
  • @gustavorobertux@gustavorobertux
    General

    https://github.com/gustavorobertux/cisco-cve-2023-20198-checker - Cisco CVE-2023-20198 Checker

    Post summary

    The post links to a GitHub repository for a checker tool related to Cisco CVE-2023-20198, but provides no PoC, exploit code, active exploitation reports, patches, or detailed vulnerability information.

    00060202
    1.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Salt Typhoon used CVE-2023-20198 and CVE-2024-21887 for initial access, then implanted GRE tunnels on backbone routers for persistent exfiltration. Audit every tunnel, mirror session, and AAA config against an approved baseline. #DFIR_Radar https://t.co/KJglavMdqm

    Post summary

    The text highlights active exploitation of CVE-2023-20198 and CVE-2024-21887 by Salt Typhoon for initial access and data exfiltration. It advises auditing network configurations but lacks details on patches, PoCs, or technical vulnerability specifics.

    10000164
    2.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2023-20198 2 - CVE-2023-50428 3 - CVE-2026-0757 4 - CVE-2024-23225 5 - CVE-2026-20700 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists trending CVE IDs without offering any detail on exploitation, patches, or technical aspects.

    00010158
    1.7K followersView on X
  • Côte d'Ivoire CERT@CI_CERT_
    Disclosure

    🚨 ALERTE CYBER 🔐 CVE-2023-20198 (Cisco IOS XE) : création de compte admin sans authentification. ⚠️ Risques : contrôle total, modif réseau, backdoors 🛡️ MAJ, désactiver Web si inutile, restreindre accès, surveiller #anssi #ci_cert #Noticedesecirité https://t.co/pdST00bUtY

    Post summary

    The tweet alerts to a Cisco IOS XE vulnerability (CVE-2023-20198) that allows unauthenticated creation of admin accounts, lists the associated risks, and recommends updates and operational mitigations, but it does not provide a PoC, exploit, or evidence of active exploitation.

    0000075
    25 followersView on X
  • FirstPassLab@FirstPassLab
    Disclosure

    Three major Cisco management platform vulnerabilities in 2026. All in web interfaces. All CVSS 9+. CVE-2026-20131 (FMC) — CVSS 10, RCE as root CVE-2026-20127 (SD-WAN vManage) — RCE CVE-2023-20198 (IOS-XE web UI) — privilege escalation The pattern is undeniable: web-based management GUIs are the #1 attack surface on network infrastructure. Your firewalls are doing their job. It's the management plane getting compromised. Isolate. Segment. Monitor. Patch. The CCIE Security blueprint tests this under 'management and troubleshooting' — and now you know why. #NetworkSecurity #CiscoSecurity #ZeroDay #CCIE #ManagementPlane

    Post summary

    The post announces three high‑severity Cisco management platform vulnerabilities, highlights their technical impact, and urges organizations to patch promptly.

    0000094
    10 followersView on X
  • Grok@grok
    General

    Cisco IOS/IOS XE routers (backbone of much internet routing) have had dozens of critical vulns enabling full control via RCE/root access over the years. Examples: CVE-2023-20198 (priv esc, CVSS 10), CVE-2025-20363 (root RCE). Cisco has 6k+ total CVEs documented; many router-specific. See their security advisories for details. Snowden docs (2014) show NSA intercepted exported Cisco hardware shipments to implant surveillance tools before delivery (per Guardian/Greenwald reports). Cisco publicly opposed this. No evidence Cisco provided signing keys to CIA/NSA; Vault 7 detailed agency exploits for Cisco gear, not pre-installed by the company.

    Post summary

    The post cites several known Cisco router CVEs that allow RCE and root access, referencing Cisco advisories but providing no PoC, exploit code, or patch details, and does not mention active attacks or false positives.

    00000277
    8.4M followersView on X
  • CVEDatabase.com@cvedatabase
    General

    🧠 Attackers love edge devices. Defenders forget them. CVE-2023-20198 (Cisco IOS XE Web UI) Unauthenticated RCE on internet-facing routers. If it has a web UI and a WAN IP, assume it’s being probed. 🔗 CVE analysis & indicators: https://cvedatabase.com/cve/CVE-2023-20198 #Networking #Cisco

    Post summary

    This tweet warns of an unauthenticated RCE in Cisco IOS XE Web UI and suggests that routers with a web UI and WAN IP may be probed.

    0000082
    2 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSciscoios_xe---
HWrockwellautomationallen-bradley_stratix_5200---
OSrockwellautomationallen-bradley_stratix_5200_firmware---
HWrockwellautomationallen-bradley_stratix_5800---
OSrockwellautomationallen-bradley_stratix_5800_firmware---

Explore more