{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-20273",
  "revision": 1,
  "title": "Cisco routers — web interface commands that run as root",
  "summary": "The web interface of Cisco's router software (IOS XE) does not check what it is given, so an account created through the companion flaw injects commands that the device executes with root privileges. Cisco names this as the step that wrote the implant.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.2,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.89634,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2023-10-23",
    "prerequisites": "An account on the device's web interface, which the paired flaw supplies."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1059"
  ],
  "kill_chain": "privilege_escalation",
  "recommended_action": "Install the fixed Cisco release, and take the web interface off the internet — the implant found on these devices was written through this flaw.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-20273",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-20273",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-20273",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-20273",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z"
    }
  ],
  "published_at": "2023-10-25T18:17:23.017Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "cisco",
    "ios-xe",
    "router",
    "command-injection",
    "exploit-chain",
    "kev"
  ]
}
