On 16 October 2023 Cisco disclosed active exploitation of CVE-2023-20198, a vulnerability in the web user interface of IOS XE software. It carries a CVSS score of 10.0 and allows an unauthenticated attacker to create a highly privileged local account on the device.
Cisco’s analysts described the actor then using a further flaw to install an implant. A second vulnerability, CVE-2023-20273, was subsequently identified as part of the chain.
The Management Interface Was The Attack Surface
The web UI exists so administrators can configure the device without a console. Exposing it to the internet turns the administrative plane into a public endpoint, and the flaw meant reaching that endpoint was sufficient.
The corpus records the same category error at 26-0609 for an unauthenticated ServiceNow API and at 26-0311, where edge appliances became the dominant initial-access route across the year. Management interfaces are built on the assumption that whoever reaches them is already trusted.
Counted By Scanning, Not By Notification
Researchers scanning the internet identified implanted devices in the tens of thousands within days of disclosure. That is a genuinely useful number and it is a different kind of number from the ones this database usually carries.
A scan counts what is visible from outside. It cannot see devices behind other controls, it counts hosts rather than organisations, and its accuracy depends on the implant remaining detectable — which changed as the campaign progressed. The corpus treats scan-derived figures as evidence of scale, never as a victim count.
A Router Is Not A Server
The compromised population here is network infrastructure. It rarely runs endpoint tooling, is rarely covered by the same patch cadence as servers, and sits in the path of everything the organisation does.
The corpus argues the same at 23-0208 for hypervisors: layers below the operating system are where an attacker gets the widest view and the smallest chance of being seen.
Built on Cisco Talos’s account of active exploitation and on Cisco’s own security advisory for the web UI vulnerabilities, both retrieved and read by this desk. The CVSS score, the chain with CVE-2023-20273 and the implant behaviour are Cisco’s. The counts of implanted devices are from third-party internet scanning as reported, are stated as such, and are deliberately not recorded as a victim count — scanning counts hosts, not organisations. No actor attribution is made: Cisco did not name one at disclosure and this desk does not infer one. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.