Cisco confirmed active exploitation in 2023 of two vulnerabilities in the web-management feature of Cisco IOS XE: CVE-2023-20198 and CVE-2023-20273. A device may be exposed if it runs IOS XE and has the Web UI enabled with ip http server or ip http secure-server. Check the running configuration, restrict or disable management access as Cisco advises, and verify the correct fixed software for your platform. This is a historical 2023 warning, not a newly reported 2026 zero-day.
What Cisco reported
Cisco’s Product Security Incident Response Team said it was aware of active exploitation of the vulnerabilities. The advisory, first published October 16, 2023 and updated through November 1, 2023, describes a two-stage attack against the IOS XE Web UI. Cisco’s October 2023 Cyber Vision knowledge-base release notes also corroborate the warning.
- Attackers exploited CVE-2023-20198 to create a local account with privilege level 15. Cisco assigned this vulnerability a CVSS score of 10.0.
- They then exploited CVE-2023-20273 to elevate privileges to root and write an implant to the device filesystem. Cisco assigned this vulnerability a CVSS score of 7.2.
The scores are Cisco’s ratings in its advisory; they are not estimates of how many devices were affected. The sources do not establish an incident-wide victim or device count.
Which devices could be affected?
The advisory concerns Cisco IOS XE with its Web UI enabled—not every product described as Cisco IOS. Cisco identifies ip http server or ip http secure-server in the configuration as enabling the relevant feature. Cisco listed classic IOS and IOS XE before Release 16 among products confirmed not vulnerable to these vulnerabilities.
Recommended Free Tools
#1 Best Overall
- SWITCH PORTS: 16 -Port 10/100/1000
- SIMPLE: Plug-and-play without a need for IT know-how or support.
- FLEXIBLE: Extensive portfolio provides ultimate flexibility from 5 to 24 ports and PoE combinations
- PERFORMANCE: Gigabit Ethernet and integrated quality-of-service (QoS) intelligence optimize delay-sensitive services and improve overall network performance.
- INNOVATIVE DESIGN: Elegant and compact design, ideal for installation outside of wiring closet such as retail stores, open plan offices, and classrooms
Having IOS XE alone does not establish exposure. Check the configuration and confirm the platform and software release against Cisco’s IOS XE Web UI security advisory and Cisco Software Checker.
How to check the running configuration
- Connect to the device using an authorized management session.
- Run
show running-config | include ip http server|secure|active. - Look for
ip http serverorip http secure-server. If either appears, the Web UI is enabled. Also review any matching active-session-module settings. - Use the platform and exact IOS XE release to check the advisory’s applicability and fixed-release guidance before planning a software change.
Cisco says ip http active-session-modules none makes the vulnerabilities not exploitable over HTTP, while ip http secure-active-session-modules none makes them not exploitable over HTTPS. These are protocol-specific controls; assess the relevant management path and device configuration rather than assuming one setting covers both.
Rank #2
- SWITCH PORTS: 5 -Port 10/100/1000
- SIMPLE: Plug-and-play without a need for IT know-how or support.
- FLEXIBLE: Extensive portfolio provides ultimate flexibility from 5 to 24 ports and PoE combinations
- PERFORMANCE: Gigabit Ethernet and integrated quality-of-service (QoS) intelligence optimize delay-sensitive services and improve overall network performance.
- INNOVATIVE DESIGN: Elegant and compact design, ideal for installation outside of wiring closet such as retail stores, open plan offices, and classrooms
What administrators should do
Reduce exposure while planning remediation
Cisco recommended disabling the HTTP Server feature on internet-facing devices or restricting access to trusted source addresses. If both HTTP and HTTPS server commands are in use, both must be disabled to turn off the feature. Before changing management settings, check whether production services or administrative workflows depend on them; Cisco warns that mitigation changes can interrupt services. Save the configuration after applying an approved change.
Install a fixed release suitable for the device
Cisco’s advisory lists IOS XE 17.9.4a, 17.6.6a, and 17.3.8a as fixed releases for their applicable trains, and 16.12.10a for Catalyst 3650 and 3850 only. Cisco also identified software maintenance updates for specified base releases. These are the advisory’s historical fix references, not a universal upgrade recommendation: verify platform support, release-train applicability, compatibility, and entitlement for the specific device before upgrading.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Rank #3
- Cisco Catalyst 2960X-48LPS-L Ethernet Switch - 48 Ports - Manageable - 48 x POE - 5 x Expansion Slots - 10/100/1000Base-T - PoE Ports - Rack-mountable
- Cisco Catalyst 2960X-48LPS-L Ethernet Switch
- 48 Ports - Manageable - 48 x POE - 5 x Expansion Slots - 10/100/1000Base-T - PoE Ports - Rack-mountable
Do not confuse this incident with the 2026 hardening advisory
Cisco’s separate IOS XE Software Security Hardening Release: August 2026, updated October 2, 2026, discusses issues found in internal testing and says they were not known to be actively exploited. It is distinct from the 2023 Web UI exploitation described above.
Quick Recap
Best Value
- GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
- PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
- FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
- SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
- REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
Rank #4
- 𝗙𝗶𝘃𝗲 𝟮.𝟱 𝗚𝗯𝗽𝘀 𝗣𝗼𝗿𝘁𝘀 𝗳𝗼𝗿 𝗦𝘂𝗽𝗲𝗿-𝗙𝗮𝘀𝘁 𝗖𝗼𝗻𝗻𝗲𝗰𝘁𝗶𝗼𝗻𝘀: 5× 2.5-Gigabit ports unlock the highest performance of your Multi-Gig bandwidth and devices, and provide up to 25 Gbps of switching capacity.
- 𝗔𝘂𝘁𝗼-𝗡𝗲𝗴𝗼𝘁𝗶𝗮𝘁𝗶𝗼𝗻: Auto-negotiation intelligently senses the link speeds and adjusts between 3-speeds (100Mb/1G/2.5G) for compatibility and optimal performance for all your devices, including 2.5G WiFi 6 AP, 2.5G NAS, 2.5G PCIe Adapter, 2.5G Server, gaming computer, 4K video, and more.
- 𝗜𝗱𝗲𝗮𝗹 𝗳𝗼𝗿 𝗩𝗮𝗿𝗶𝗼𝘂𝘀 𝗦𝗰𝗲𝗻𝗮𝗿𝗶𝗼𝘀: Built for LAN parties, home entertainment, small and home offices, and instant transfer for workstations.
- 𝗛𝗮𝘀𝘀𝗹𝗲-𝗙𝗿𝗲𝗲 𝗖𝗮𝗯𝗹𝗶𝗻𝗴: Instantly upgrade to 2.5 Gbps without the need to upgrade to Cat6 wiring, reducing wiring costs and hassle. *
- 𝗦𝗶𝗹𝗲𝗻𝘁 𝗢𝗽𝗲𝗿𝗮𝘁𝗶𝗼𝗻: Industry-leading fanless design ensures silent operation, ideal for any home or business.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

