Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2023-20198

10.0 · CRITICAL Actively Exploited
Published Oct 16, 2023 rockwellautomation CWE-420 EPSS 99.57% (100th pctl)

Overview

CVE-2023-20198 is a critical-severity vulnerability affecting rockwellautomation allen-bradley_stratix_5200_firmware. It was published on October 16, 2023 and has a CVSS 3.1 base score of 10.0 (CRITICAL). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

This vulnerability has a CVSS 3.1 base score of 10.0, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

Remediation

Check the references section for vendor advisories and patches from rockwellautomation. Update allen-bradley_stratix_5200_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
rockwellautomation allen-bradley_stratix_5200_firmware >= 0, < 17.12.02 Affected
rockwellautomation allen-bradley_stratix_5800_firmware >= 0, < 17.12.02 Affected
cisco ios_xe >= 16.12, < 16.12.10a Affected

Frequently Asked Questions

What is CVE-2023-20198?

CVE-2023-20198 is a critical-severity vulnerability affecting rockwellautomation allen-bradley_stratix_5200_firmware. It was published on October 16, 2023 and has a CVSS 3.1 base score of 10.0 (CRITICAL). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.

How severe is CVE-2023-20198?

This vulnerability has a CVSS 3.1 base score of 10.0, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2023-20198?

Check the references section for vendor advisories and patches from rockwellautomation. Update allen-bradley_stratix_5200_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2023-20198?

CyberStrike's AI-powered security agents can automatically detect CVE-2023-20198 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.