Known Exploited Vulnerability
7.2
HIGH CVSS 3.1
CVE-2023-20273
Cisco IOS XE Web UI Command Injection Vulnerability - [Actively Exploited]
Description

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.

INFO

Published Date :

Oct. 25, 2023, 6:17 p.m.

Last Modified :

April 2, 2025, 6:19 p.m.

Remotely Exploit :

Yes !
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

Required Action :

Verify that instances of Cisco IOS XE Web UI are in compliance with BOD 23-02 and apply mitigations per vendor instructions. For affected products (Cisco IOS XE Web UI exposed to the internet or to untrusted networks), follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.

Notes :

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z; https://nvd.nist.gov/vuln/detail/CVE-2023-20273

Affected Products

The following products are affected by CVE-2023-20273 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Cisco ios_xe
2 Cisco catalyst_3650
3 Cisco catalyst_3650-12x48fd-e
4 Cisco catalyst_3650-12x48fd-l
5 Cisco catalyst_3650-12x48fd-s
6 Cisco catalyst_3650-12x48uq
7 Cisco catalyst_3650-12x48uq-e
8 Cisco catalyst_3650-12x48uq-l
9 Cisco catalyst_3650-12x48uq-s
10 Cisco catalyst_3650-12x48ur
11 Cisco catalyst_3650-12x48ur-e
12 Cisco catalyst_3650-12x48ur-l
13 Cisco catalyst_3650-12x48ur-s
14 Cisco catalyst_3650-12x48uz
15 Cisco catalyst_3650-12x48uz-e
16 Cisco catalyst_3650-12x48uz-l
17 Cisco catalyst_3650-12x48uz-s
18 Cisco catalyst_3650-24pd
19 Cisco catalyst_3650-24pd-e
20 Cisco catalyst_3650-24pd-l
21 Cisco catalyst_3650-24pd-s
22 Cisco catalyst_3650-24pdm
23 Cisco catalyst_3650-24pdm-e
24 Cisco catalyst_3650-24pdm-l
25 Cisco catalyst_3650-24pdm-s
26 Cisco catalyst_3650-24ps-e
27 Cisco catalyst_3650-24ps-l
28 Cisco catalyst_3650-24ps-s
29 Cisco catalyst_3650-24td-e
30 Cisco catalyst_3650-24td-l
31 Cisco catalyst_3650-24td-s
32 Cisco catalyst_3650-24ts-e
33 Cisco catalyst_3650-24ts-l
34 Cisco catalyst_3650-24ts-s
35 Cisco catalyst_3650-48fd-e
36 Cisco catalyst_3650-48fd-l
37 Cisco catalyst_3650-48fd-s
38 Cisco catalyst_3650-48fq
39 Cisco catalyst_3650-48fq-e
40 Cisco catalyst_3650-48fq-l
41 Cisco catalyst_3650-48fq-s
42 Cisco catalyst_3650-48fqm
43 Cisco catalyst_3650-48fqm-e
44 Cisco catalyst_3650-48fqm-l
45 Cisco catalyst_3650-48fqm-s
46 Cisco catalyst_3650-48fs-e
47 Cisco catalyst_3650-48fs-l
48 Cisco catalyst_3650-48fs-s
49 Cisco catalyst_3650-48pd-e
50 Cisco catalyst_3650-48pd-l
51 Cisco catalyst_3650-48pd-s
52 Cisco catalyst_3650-48pq-e
53 Cisco catalyst_3650-48pq-l
54 Cisco catalyst_3650-48pq-s
55 Cisco catalyst_3650-48ps-e
56 Cisco catalyst_3650-48ps-l
57 Cisco catalyst_3650-48ps-s
58 Cisco catalyst_3650-48td-e
59 Cisco catalyst_3650-48td-l
60 Cisco catalyst_3650-48td-s
61 Cisco catalyst_3650-48tq-e
62 Cisco catalyst_3650-48tq-l
63 Cisco catalyst_3650-48tq-s
64 Cisco catalyst_3650-48ts-e
65 Cisco catalyst_3650-48ts-l
66 Cisco catalyst_3650-48ts-s
67 Cisco catalyst_3650-8x24pd-e
68 Cisco catalyst_3650-8x24pd-l
69 Cisco catalyst_3650-8x24pd-s
70 Cisco catalyst_3650-8x24uq
71 Cisco catalyst_3650-8x24uq-e
72 Cisco catalyst_3650-8x24uq-l
73 Cisco catalyst_3650-8x24uq-s
74 Cisco catalyst_3850
75 Cisco catalyst_3850-12s-e
76 Cisco catalyst_3850-12s-s
77 Cisco catalyst_3850-12x48u
78 Cisco catalyst_3850-12xs-e
79 Cisco catalyst_3850-12xs-s
80 Cisco catalyst_3850-16xs-e
81 Cisco catalyst_3850-16xs-s
82 Cisco catalyst_3850-24p-e
83 Cisco catalyst_3850-24p-l
84 Cisco catalyst_3850-24p-s
85 Cisco catalyst_3850-24pw-s
86 Cisco catalyst_3850-24s-e
87 Cisco catalyst_3850-24s-s
88 Cisco catalyst_3850-24t-e
89 Cisco catalyst_3850-24t-l
90 Cisco catalyst_3850-24t-s
91 Cisco catalyst_3850-24u
92 Cisco catalyst_3850-24u-e
93 Cisco catalyst_3850-24u-l
94 Cisco catalyst_3850-24u-s
95 Cisco catalyst_3850-24xs
96 Cisco catalyst_3850-24xs-e
97 Cisco catalyst_3850-24xs-s
98 Cisco catalyst_3850-24xu
99 Cisco catalyst_3850-24xu-e
100 Cisco catalyst_3850-24xu-l
101 Cisco catalyst_3850-24xu-s
102 Cisco catalyst_3850-32xs-e
103 Cisco catalyst_3850-32xs-s
104 Cisco catalyst_3850-48f-e
105 Cisco catalyst_3850-48f-l
106 Cisco catalyst_3850-48f-s
107 Cisco catalyst_3850-48p-e
108 Cisco catalyst_3850-48p-l
109 Cisco catalyst_3850-48p-s
110 Cisco catalyst_3850-48pw-s
111 Cisco catalyst_3850-48t-e
112 Cisco catalyst_3850-48t-l
113 Cisco catalyst_3850-48t-s
114 Cisco catalyst_3850-48u
115 Cisco catalyst_3850-48u-e
116 Cisco catalyst_3850-48u-l
117 Cisco catalyst_3850-48u-s
118 Cisco catalyst_3850-48xs
119 Cisco catalyst_3850-48xs-e
120 Cisco catalyst_3850-48xs-f-e
121 Cisco catalyst_3850-48xs-f-s
122 Cisco catalyst_3850-48xs-s
123 Cisco catalyst_3850-nm-2-40g
124 Cisco catalyst_3850-nm-8-10g
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH [email protected]
CVSS 3.1 HIGH [email protected]
Solution
To address the command injection vulnerability, update Cisco IOS XE Software to a patched version.
  • Apply the appropriate patch or upgrade to a fixed version of Cisco IOS XE Software.
  • Consult the vendor advisory for specific mitigation steps.
Public PoC/Exploit Available at Github

CVE-2023-20273 has a 15 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2023-20273.

URL Resource
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z Vendor Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z Vendor Advisory
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2023-20273 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Updated: 1 week ago
0 stars 0 fork 0 watcher
Born at : Sept. 9, 2025, 6:09 a.m. This repo has been linked 24 different CVEs too.

None

Python Shell HTML JavaScript PowerShell TeX

Updated: 4 months ago
0 stars 0 fork 0 watcher
Born at : May 13, 2025, 1:16 p.m. This repo has been linked 5 different CVEs too.

Exploit PoC for CVE-2023-20198

Python

Updated: 4 months ago
2 stars 0 fork 0 watcher
Born at : April 11, 2025, 3:37 p.m. This repo has been linked 2 different CVEs too.

None

Python

Updated: 1 year ago
0 stars 0 fork 0 watcher
Born at : Aug. 26, 2024, 8:16 a.m. This repo has been linked 2 different CVEs too.

None

Updated: 9 months, 4 weeks ago
0 stars 0 fork 0 watcher
Born at : June 26, 2024, 5:33 a.m. This repo has been linked 2 different CVEs too.

CVE-2023-20273 Exploit PoC

Python

Updated: 2 months, 3 weeks ago
11 stars 3 fork 3 watcher
Born at : Dec. 9, 2023, 7:25 a.m. This repo has been linked 1 different CVEs too.

CVE-2023-20198 Exploit PoC

Python

Updated: 2 months, 1 week ago
52 stars 12 fork 12 watcher
Born at : Nov. 16, 2023, 4:39 p.m. This repo has been linked 2 different CVEs too.

Checks the status of 'ip http server' and 'ip http secure-server' on Cisco networking devices

PowerShell

Updated: 1 year, 10 months ago
0 stars 0 fork 0 watcher
Born at : Nov. 2, 2023, 4:35 p.m. This repo has been linked 2 different CVEs too.

This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273

Python

Updated: 6 months, 1 week ago
30 stars 5 fork 5 watcher
Born at : Oct. 23, 2023, 7:25 p.m. This repo has been linked 2 different CVEs too.

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

cisco cisco-ios-xe cve-2023-20198 cve-2023-20273 iocisco pcap suricata badcandy

Python

Updated: 3 months ago
39 stars 8 fork 8 watcher
Born at : Oct. 23, 2023, 2:52 p.m. This repo has been linked 3 different CVEs too.

Free and libre source BadUSB payloads for Flipper Zero. [Windows, GNU/Linux, iOS]

flipper-zero flipperzero flipper-badusb flipper-zero-payload hak5 rubberducky badusb duckyscript linux open-source windows free badusb-payloads free-payloads ios iphone

PowerShell Python Shell HTML JavaScript TeX

Updated: 1 month, 4 weeks ago
1492 stars 112 fork 112 watcher
Born at : Jan. 4, 2023, 10:05 a.m. This repo has been linked 5 different CVEs too.

Collect some iot-related security articles, including vulnerability analysis, security conferences and papers, etc.

iot-security

Updated: 1 month, 4 weeks ago
285 stars 29 fork 29 watcher
Born at : Dec. 6, 2022, 1:11 p.m. This repo has been linked 47 different CVEs too.

awesome iot exploit resource

iot security awesome awesome-list firmware hardware-hacking iot-device iot-security embedded exploit vulnerability

Updated: 1 month, 4 weeks ago
58 stars 5 fork 5 watcher
Born at : Nov. 13, 2022, 11:03 p.m. This repo has been linked 25 different CVEs too.

Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.

cisa-kev vulnerability 0day cisa exploits

Updated: 1 month, 1 week ago
581 stars 42 fork 42 watcher
Born at : April 19, 2022, 8:58 a.m. This repo has been linked 1287 different CVEs too.

None

Updated: 1 year, 2 months ago
1 stars 0 fork 0 watcher
Born at : Nov. 16, 2020, 2:26 p.m. This repo has been linked 5 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2023-20273 vulnerability anywhere in the article.

  • SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 35

The Good | Interpol Cracks Down on Cybercrime as U.S. Sanctions North Korean IT Scheme Interpol announced the arrest of over 1200 suspects in Operation Serengeti 2.0, a three-month crackdown on cyberc ... Read more

Published Date: Aug 29, 2025 (2 weeks, 6 days ago)
  • SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 35

The Good | Interpol Cracks Down on Cybercrime as U.S. Sanctions North Korean IT Scheme Interpol announced the arrest of over 1200 suspects in Operation Serengeti 2.0, a three-month crackdown on cyberc ... Read more

Published Date: Aug 29, 2025 (2 weeks, 6 days ago)
  • The Hacker News
Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide

The China-linked advanced persistent threat (APT) actor known as Salt Typhoon has continued its attacks targeting networks across the world, including organizations in the telecommunications, governme ... Read more

Published Date: Aug 28, 2025 (3 weeks ago)
  • Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
UK and US Blame Three Chinese Tech Firms for Global Cyberattacks

A coalition of international cybersecurity agencies led by the UK’s National Cyber Security Centre (NCSC) has publicly linked three China-based technology companies to a long-running global cyberattac ... Read more

Published Date: Aug 28, 2025 (3 weeks ago)
  • CybersecurityNews
CISA Publish Hunting and Mitigation Guide to Defend Networks from Chinese State-Sponsored Actors

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside the NSA, FBI, and a broad coalition of international partners, has released a comprehensive cybersecurity advisory detailing ... Read more

Published Date: Aug 28, 2025 (3 weeks, 1 day ago)
  • The Register
If you thought China's Salt Typhoon was booted off critical networks, think again

China's Salt Typhoon cyberspies continue their years-long hacking campaign targeting critical industries around the world, according to a joint security alert from cyber and law enforcement agencies a ... Read more

Published Date: Aug 28, 2025 (3 weeks, 1 day ago)
  • Daily CyberSecurity
An Espionage System: NSA, CISA, & Partners Expose Chinese APT Groups

In a multinational alert, the U.S. National Security Agency (NSA), CISA, FBI, and partners from more than a dozen allied nations have released a Joint Cybersecurity Advisory (CSA) exposing how Chinese ... Read more

Published Date: Aug 28, 2025 (3 weeks, 1 day ago)
  • BleepingComputer
Global Salt Typhoon hacking campaigns linked to Chinese tech firms

The U.S. National Security Agency (NSA), the UK's National Cyber Security Centre (NCSC), and partners from over a dozen countries have linked the Salt Typhoon global hacking campaigns to three China-b ... Read more

Published Date: Aug 27, 2025 (3 weeks, 1 day ago)
  • BleepingComputer
Chinese hackers breached National Guard to steal network configurations

The Chinese state-sponsored hacking group known as Salt Typhoon breached and remained undetected in a U.S. Army National Guard network for nine months in 2024, stealing network configuration files and ... Read more

Published Date: Jul 17, 2025 (2 months ago)
  • The Hacker News
Chinese Hackers Target Taiwan's Semiconductor Sector with Cobalt Strike, Custom Backdoors

The Taiwanese semiconductor industry has become the target of spear-phishing campaigns undertaken by three Chinese state-sponsored threat actors. "Targets of these campaigns ranged from organizations ... Read more

Published Date: Jul 17, 2025 (2 months ago)
  • The Hacker News
China-linked Salt Typhoon Exploits Critical Cisco Vulnerability to Target Canadian Telecom

Cyber Espionage / Chinese Hackers The Canadian Centre for Cyber Security and the U.S. Federal Bureau of Investigation (FBI) have issued an advisory warning of cyber attacks mounted by the China-linked ... Read more

Published Date: Jun 24, 2025 (2 months, 3 weeks ago)
  • Ars Technica
Canadian telecom hacked by suspected China state group

Hackers suspected of working on behalf of the Chinese government exploited a maximum-severity vulnerability, which had received a patch 16 months earlier, to compromise a telecommunications provider i ... Read more

Published Date: Jun 23, 2025 (2 months, 3 weeks ago)
  • security.nl
Securitybedrijf meldt actief misbruik van jarenoude Cisco-kwetsbaarheden

Aanvallers maken actief misbruik van jarenoude kwetsbaarheden in apparatuur van Cisco, waaronder een kritiek beveiligingslek dat sinds 28 maart 2018 bekend is. Dat laat securitybedrijf GreyNoise op ba ... Read more

Published Date: Feb 25, 2025 (6 months, 3 weeks ago)
  • Cyber Security News
100+ Malicious IPs Actively Exploiting Vulnerabilities in Cisco Devices

A malicious campaign targeting Cisco networking equipment through two critical vulnerabilities, with state-backed actors and other actors exploiting unpatched systems. GreyNoise Intelligence has ident ... Read more

Published Date: Feb 25, 2025 (6 months, 3 weeks ago)
  • The Hacker News
Two Actively Exploited Security Flaws in Adobe and Oracle Products Flagged by CISA

Network Security / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws impacting Adobe ColdFusion and Oracle Agile Product Lifecycle Management ... Read more

Published Date: Feb 25, 2025 (6 months, 3 weeks ago)
  • Dark Reading
Cisco Confirms Salt Typhoon Exploitation in Telecom Hits

Source: Geopix / Alamy Stock PhotoNEWS BRIEFFollowing research reports last week that Salt Typhoon, the Chinese threat actor known for spying on communications networks, exploited a Cisco vulnerabilit ... Read more

Published Date: Feb 21, 2025 (6 months, 4 weeks ago)
  • The Hacker News
Cisco Confirms Salt Typhoon Exploited CVE-2018-0171 to Target U.S. Telecom Networks

Network Security / Vulnerability Cisco has confirmed that a Chinese threat actor known as Salt Typhoon gained access by likely abusing a known security flaw tracked as CVE-2018-0171, and by obtaining ... Read more

Published Date: Feb 21, 2025 (6 months, 4 weeks ago)
  • The Cyber Express
December 2024 Cyble Report: Malware, Phishing, and IoT Vulnerabilities on the Rise

The latest Sensor Intelligence Report from Cyble, dated December 4–10, 2024, sheds light on a troubling increase in cyber threats, including malware intrusions, phishing scams, and attacks targeting v ... Read more

Published Date: Dec 16, 2024 (9 months ago)
  • TheCyberThrone
Top 15 Most Exploited Vulnerabilities in 2023

In a joint cybersecurity advisory, the security agencies across the world have identified the most exploited vulnerabilities of 2023. This advisory, coauthored by the Cybersecurity and Infrastructure ... Read more

Published Date: Nov 16, 2024 (10 months ago)
  • The Register
Five Eyes infosec agencies list 2024's most exploited software flaws

The cyber security agencies of the UK, US, Canada, Australia, and New Zealand have issued their annual list of the 15 most exploited vulnerabilities, and warned that attacks on zero-day exploits have ... Read more

Published Date: Nov 14, 2024 (10 months ago)

The following table lists the changes that have been made to the CVE-2023-20273 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Modified Analysis by [email protected]

    Apr. 02, 2025

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:o:cisco:ios_xe:16.2.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.1.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.1.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.1.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.4.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.2.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.4:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.5b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.6:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.4.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.5.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.5.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.5.1b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.5:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.7:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.8:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.4.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.5.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.5.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.4:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.7.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.7.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.7.1b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.7.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.7.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.8.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.8.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.8.1b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.8.1s:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.8.1c:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.8.1d:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.8.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.8.1e:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.1b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.1s:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.9:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.10:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.5:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.4a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.5a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.6:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.7:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.8:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.7.4:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.8.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.4:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.3a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.5:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.5f:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.1b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.1s:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.1c:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.1e:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.1d:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.1f:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.1g:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.10.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.11.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.11.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.11.1b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.11.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.11.1s:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.1s:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.1c:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.1w:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.1y:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.2a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.8:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.1x:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.1t:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.4:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.1.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.2.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.3.11:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.9:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.6.10:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.6:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.7:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.9.8:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.2s:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.3s:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.3a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.4a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.5:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.6:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.1z1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.5a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.5b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.1z2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.6a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.7:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.9:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:16.12.10:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.1.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.1.1s:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.1.1t:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.1.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.2.1r:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.2.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.2.1v:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.2.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.2.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.1w:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.2a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.1x:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.1z:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.4:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.5:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.4a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.6:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.4b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.4c:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.5a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.5b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.7:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.3.8:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.4.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.4.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.4.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.4.1b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.4.2a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.5.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.5.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.5.1b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.5.1c:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.1w:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.1x:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.1y:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.1z:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.3a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.4:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.1z1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.5:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.6.6:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.7.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.7.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.7.1b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.7.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.10.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.10.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.10.1b:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.8.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.8.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.1w:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.2:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.1x:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.1y:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.3:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.2a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.1x1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.3a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.4:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.9.1y1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.11.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.11.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.12.1:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.12.1a:*:*:*:*:*:*:* *cpe:2.3:o:cisco:ios_xe:17.11.99sw:*:*:*:*:*:*:*
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z
  • Modified Analysis by [email protected]

    Jun. 17, 2024

    Action Type Old Value New Value
    Removed CWE NIST NVD-CWE-noinfo
    Added CWE NIST CWE-78
  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • CVE Modified by [email protected]

    Jan. 25, 2024

    Action Type Old Value New Value
    Removed Reference Cisco Systems, Inc. http://packetstormsecurity.com/files/175674/Cisco-IOX-XE-Unauthenticated-Remote-Code-Execution.html
    Added CWE Cisco Systems, Inc. CWE-78
  • Modified Analysis by [email protected]

    Nov. 15, 2023

    Action Type Old Value New Value
    Changed Reference Type http://packetstormsecurity.com/files/175674/Cisco-IOX-XE-Unauthenticated-Remote-Code-Execution.html No Types Assigned http://packetstormsecurity.com/files/175674/Cisco-IOX-XE-Unauthenticated-Remote-Code-Execution.html Exploit, Third Party Advisory, VDB Entry
  • CVE Modified by [email protected]

    Nov. 14, 2023

    Action Type Old Value New Value
    Added Reference Cisco Systems, Inc. http://packetstormsecurity.com/files/175674/Cisco-IOX-XE-Unauthenticated-Remote-Code-Execution.html [No types assigned]
  • CVE Modified by [email protected]

    Nov. 07, 2023

    Action Type Old Value New Value
    Changed Description A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges. A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
  • Initial Analysis by [email protected]

    Oct. 31, 2023

    Action Type Old Value New Value
    Added CVSS V3.1 NIST AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Changed Reference Type https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z No Types Assigned https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z Vendor Advisory
    Added CWE NIST NVD-CWE-noinfo
    Added CPE Configuration OR *cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* versions from (including) 17.3 up to (excluding) 17.3.8a *cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* versions from (including) 17.6 up to (excluding) 17.6.6a *cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* versions from (including) 17.9 up to (excluding) 17.9.4a
    Added CPE Configuration AND OR *cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* versions from (including) 16.12 up to (excluding) 16.12.10a OR cpe:2.3:h:cisco:catalyst_3650:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48fd-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48fd-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48fd-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48uq:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48uq-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48uq-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48uq-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48ur:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48ur-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48ur-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48ur-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48uz:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48uz-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48uz-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-12x48uz-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24pd:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24pd-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24pd-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24pd-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24pdm:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24pdm-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24pdm-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24pdm-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24ps-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24ps-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24ps-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24td-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24td-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24td-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24ts-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24ts-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-24ts-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fd-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fd-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fd-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fq:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fq-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fq-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fq-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fqm:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fqm-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fqm-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fqm-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fs-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fs-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48fs-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48pd-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48pd-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48pd-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48pq-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48pq-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48pq-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48ps-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48ps-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48ps-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48td-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48td-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48td-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48tq-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48tq-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48tq-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48ts-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48ts-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-48ts-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-8x24pd-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-8x24pd-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-8x24pd-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-8x24uq:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-8x24uq-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-8x24uq-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3650-8x24uq-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-12s-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-12s-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-12x48u:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-12xs-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-12xs-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-16xs-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-16xs-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24p-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24p-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24p-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24pw-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24s-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24s-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24t-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24t-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24t-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24u:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24u-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24u-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24u-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24xs:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24xs-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24xs-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24xu:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24xu-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24xu-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-24xu-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-32xs-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-32xs-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48f-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48f-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48f-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48p-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48p-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48p-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48pw-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48t-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48t-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48t-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48u:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48u-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48u-l:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48u-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48xs:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48xs-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48xs-f-e:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48xs-f-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-48xs-s:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-nm-2-40g:-:*:*:*:*:*:*:* cpe:2.3:h:cisco:catalyst_3850-nm-8-10g:-:*:*:*:*:*:*:*
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 7.2
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

91.74 }} -0.05%

score

0.99670

percentile