{"id":"CVE-2023-20198","vendor_project":"Cisco","product":"IOS XE Web UI","vulnerability_name":"Cisco IOS XE Web UI Privilege Escalation Vulnerability","date_added":"2023-10-16","due_date":"2023-10-20","known_ransomware_use":"Unknown","short_description":"Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.","required_action":"Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.","cwes":"CWE-420","cvss_version":"3.1","cvss_severity":"CRITICAL","cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","nvd_published":"2023-10-16","nvd_status":"Analyzed","epss":0.99571,"epss_percentile":0.99946,"cvss_score":10,"days_published_to_kev":0,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2023-20198","by":"CyberMax"}