ExtraHop named a Leader in the 2025 Forrester Wave™: Network Analysis And Visibility Solutions

Search
  • Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

Cisco IOS XE Exploit - CVE-2023-20198

Risk Factors

Internet-facing devices with the Cisco IOS XE web UI service enabled have been exploited. An unauthenticated attacker can gain control of a device, access sensitive traffic, and launch attacks on additional networks.

Category

Exploitation
Detection diagram
Next in Exploitation: Citrix ADC and Gateway Exploit - CVE-2019-19781

Attack Background

The web interface of Cisco Internetworking Operating System (IOS) XE has a privilege escalation vulnerability that allows attackers to create an account with administrator (level 15) privileges. To exploit this vulnerability, the attacker sends a malicious HTTP request with a SOAP payload and a double URL-encoded URI that specifies the /webui_wsma_http or /webui_wsma_https endpoints. These endpoints are normally restricted, but the vulnerability enables the restriction to be bypassed (1). The victim processes the payload and sends an HTTP response with a SOAP payload that contains the account information and a 200 status code to the attacker (2). After the account is created, the attacker can chain this exploit with an exploit of CVE-2023-20273 to install malware on the device.

Mitigation Options

Upgrade to a fixed version

MITRE ATT&CK ID

Associated content

Announcing The Forrester Wave™: Network Analysis And Visibility Solutions, Q4 2025

Network analysis and visibility solutions remain underrepresented in enterprises. Find out why in this preview of a new Wave report.

Report

ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response — ExtraHop

ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response

News

Detections

Visit this resource for more information.

Docs

The 2025 ExtraHop Global Threat Landscape Report: The Alarming Reality of Threat Actor Dwell Time and Deeper Network Access — ExtraHop

This analysis exposes the critical link between an organization's lack of internal visibility and the escalating cost of compromise, demanding an urgent re-evaluation of how core business assets are protected.

Blog

ExtraHop RevealX MITRE ATT&CK Coverage 2024 — ExtraHop

Learn why you need to be wary of the claims certain network detection and response providers make about their coverage against the MITRE ATT&CK framework.

Blog

MITRE ATT&CK - Network Detection & Response with RevealX — ExtraHop

Learn how NDR from RevealX helps security teams detect and investigate more adversary TTPs in the MITRE ATT&CK framework than rule-based tools.

External
Periodic Table of Use Cases

What else can RevealX do for you?