← All CVEs NewScan detects
criticalKEV

CVE-2023-20198

IOS XE web UI privilege escalation - unauthenticated admin account creation (mass implant campaign)

Severity
critical
Affected product
Cisco IOS XE Web UI
Affected versions
Cisco IOS XE Web UI all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
Added to NewScan
2026-08-02
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Cisco IOS XE Web UI appliance and reports this CVE when the detected version falls inside the affected range below.

No version gate: the fix ships as per-train SMUs and the web UI does not publish its train anonymously, so this stays an advisory observation.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →