boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-20273

Cisco Cisco IOS XE Web UI
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .8963   99.8   YES
AFFECTED
  Product                Versions  Fixed
  Cisco IOS XE Software  16.1.1 –  —
TIMELINE
  Oct 27  Reserved by cisco
  Oct 23  Added to CISA KEV, remediation due 2023-10-27
  Oct 24  Published (CNA: cisco)
CWE-78 · CNA: cisco · CVSS v3.1 · 2 references · KEV due October 27, 2023

Description

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
October 27, 2022ReservedReserved by cisco
October 23, 2023KEV ADDEDAdded to CISA KEV, remediation due 2023-10-27
October 24, 2023PublishedPublished (CNA: cisco)

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
CiscoCisco IOS XE Software—16.1.1—

Weaknesses

CWE-78

References (2)

Related

Authoritative record: CVE-2023-20273 at cve.org

Vendors: cisco

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-20273 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.