criticalKEV
CVE-2023-20198
IOS XE web UI privilege escalation - unauthenticated admin account creation (mass implant campaign)
- Severity
- critical
- Affected product
- Cisco IOS XE Web UI
- Affected versions
- Cisco IOS XE Web UI all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Cisco IOS XE Web UI appliance and reports this CVE when the detected version falls inside the affected range below.
No version gate: the fix ships as per-train SMUs and the web UI does not publish its train anonymously, so this stays an advisory observation.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →