Desk live·
ForensicPost
Nation-state/Edge devices/File 23-1016

A CVSS 10.0 Flaw Let Anyone Create an Admin Account on Cisco IOS XE Devices

CVE-2023-20198 required no credential and no user interaction. Attackers used it to create privileged accounts on internet-facing network devices and install implants — and internet scanning found the implanted population running into the tens of thousands within days.

Constructed geometry · not a chart of case data
TargetCisco IOS XE devices
ActorUnattributed
D. Kennedy11 min readConfidence: high2 sources reviewed

On 16 October 2023 Cisco disclosed active exploitation of CVE-2023-20198, a vulnerability in the web user interface of IOS XE software. It carries a CVSS score of 10.0 and allows an unauthenticated attacker to create a highly privileged local account on the device.

Cisco’s analysts described the actor then using a further flaw to install an implant. A second vulnerability, CVE-2023-20273, was subsequently identified as part of the chain.

The Management Interface Was The Attack Surface

The web UI exists so administrators can configure the device without a console. Exposing it to the internet turns the administrative plane into a public endpoint, and the flaw meant reaching that endpoint was sufficient.

The corpus records the same category error at 26-0609 for an unauthenticated ServiceNow API and at 26-0311, where edge appliances became the dominant initial-access route across the year. Management interfaces are built on the assumption that whoever reaches them is already trusted.

Counted By Scanning, Not By Notification

Researchers scanning the internet identified implanted devices in the tens of thousands within days of disclosure. That is a genuinely useful number and it is a different kind of number from the ones this database usually carries.

A scan counts what is visible from outside. It cannot see devices behind other controls, it counts hosts rather than organisations, and its accuracy depends on the implant remaining detectable — which changed as the campaign progressed. The corpus treats scan-derived figures as evidence of scale, never as a victim count.

A Router Is Not A Server

The compromised population here is network infrastructure. It rarely runs endpoint tooling, is rarely covered by the same patch cadence as servers, and sits in the path of everything the organisation does.

The corpus argues the same at 23-0208 for hypervisors: layers below the operating system are where an attacker gets the widest view and the smallest chance of being seen.

How we reported this

Built on Cisco Talos’s account of active exploitation and on Cisco’s own security advisory for the web UI vulnerabilities, both retrieved and read by this desk. The CVSS score, the chain with CVE-2023-20273 and the implant behaviour are Cisco’s. The counts of implanted devices are from third-party internet scanning as reported, are stated as such, and are deliberately not recorded as a victim count — scanning counts hosts, not organisations. No actor attribution is made: Cisco did not name one at disclosure and this desk does not infer one. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Active exploitation of Cisco IOS XE Software Web Management User Interface vulnerabilitiesCisco Talos
  2. Multiple Vulnerabilities in Cisco IOS XE Software Web UI FeatureCisco
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary