<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:16:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-06875</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-06875</link>
      <description>bdu:2023-06875</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-06875</guid>
    </item>
    <item>
      <title>certfr-2023-ale-011 — &lt;span style="color: #ff0000;"&gt;&lt;strong&gt;\[Mise à jour du 02 novembre
2023\]&lt;/strong&gt;&lt;/span&gt;

La version 17.3.8a est dispo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-ale-011</link>
      <description>certfr-2023-ale-011</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-ale-011</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0878 — De multiples vulnérabilités ont été découvertes dans Cisco IOS XE. Elles
permettent à un attaquant de provoquer une exé…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0878</link>
      <description>certfr-2023-avi-0878</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0878</guid>
    </item>
    <item>
      <title>cisco-sa-iosxe-webui-privesc-j22SaA4z — Multiple Vulnerabilities in Cisco IOS XE Software Web UI Feature</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-iosxe-webui-privesc-j22saa4z</link>
      <description>&lt;p&gt;Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker.&#13;
&#13;
Fix information can be found in the Fixed Software [&amp;#34;#fs&amp;#34;] section of this advisory.&#13;
&#13;
Our investigation has determined that the actors exploited two previously unknown issues.&#13;
&#13;
The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access.&#13;
&#13;
The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue.&#13;
&#13;
CVE-2023-20198 has been assigned a CVSS Score of 10.0.&#13;
CVE-2023-20273 has been assigned a CVSS Score of 7.2.&#13;
&#13;
Both of these CVEs are being tracked by CSCwh87343 [&amp;#34;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh87343&amp;#34;].&#13;
&#13;
For steps to close the attack vector for these vulnerabilities, see the Recommendations [&amp;#34;#REC&amp;#34;] section of this advisory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker.&#13;
&#13;
Fix information can be found in the Fixed Software [&amp;#34;#fs&amp;#34;] section of this advisory.&#13;
&#13;
Our investigation has determined that the actors exploited two previously unknown issues.&#13;
&#13;
The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access.&#13;
&#13;
The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue.&#13;
&#13;
CVE-2023-20198 has been assigned a CVSS Score of 10.0.&#13;
CVE-2023-20273 has been assigned a CVSS Score of 7.2.&#13;
&#13;
Both of these CVEs are being tracked by CSCwh87343 [&amp;#34;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh87343&amp;#34;].&#13;
&#13;
For steps to close the attack vector for these vulnerabilities, see the Recommendations [&amp;#34;#REC&amp;#34;] section of this advisory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-iosxe-webui-privesc-j22saa4z</guid>
    </item>
    <item>
      <title>cnvd-2023-77098</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2023-77098</link>
      <description>cnvd-2023-77098</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2023-77098</guid>
    </item>
    <item>
      <title>EUVD-2026-255695</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255695</link>
      <description>EUVD-2026-255695</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255695</guid>
    </item>
    <item>
      <title>fkie_cve-2023-20198</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-20198</link>
      <description>&lt;p&gt;Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-20198</guid>
    </item>
    <item>
      <title>GHSA-4xrf-pcxr-rf3c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4xrf-pcxr-rf3c</link>
      <description>&lt;p&gt;Cisco is aware of active exploitation of a previously unknown vulnerability in the web UI feature of Cisco IOS XE Software when exposed to the internet or to untrusted networks. This vulnerability allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access. The attacker can then use that account to gain control of the affected system.&lt;/p&gt;
&lt;p&gt;For steps to close the attack vector for this vulnerability, see the Recommendations section of this advisory&lt;/p&gt;
&lt;p&gt;Cisco will provide updates on the status of this investigation and when a software patch is available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cisco is aware of active exploitation of a previously unknown vulnerability in the web UI feature of Cisco IOS XE Software when exposed to the internet or to untrusted networks. This vulnerability allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access. The attacker can then use that account to gain control of the affected system.&lt;/p&gt;
&lt;p&gt;For steps to close the attack vector for this vulnerability, see the Recommendations section of this advisory&lt;/p&gt;
&lt;p&gt;Cisco will provide updates on the status of this investigation and when a software patch is available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4xrf-pcxr-rf3c</guid>
    </item>
    <item>
      <title>gsd-2023-20198</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-20198</link>
      <description>gsd-2023-20198</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-20198</guid>
    </item>
    <item>
      <title>ICSA-23-297-01 — Rockwell Automation Stratix 5800 and Stratix 5200 (UPDATE A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-297-01</link>
      <description>&lt;p&gt;Rockwell Automation is aware of active exploitation of a previously unknown vulnerability in the web user interface feature of Cisco IOS XE Software when exposed to the internet or to untrusted networks. This vulnerability allows a remote, unauthenticated threat actor to create an account on a vulnerable system with privilege level 15 access. The threat actor could then potentially use that account to gain control of the affected system. Rockwell Automation is aware of active exploitation of a previously unknown vulnerability in the Web UI feature of Cisco IOS XE Software when exposed to the internet or to untrusted networks. This vulnerability could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rockwell Automation is aware of active exploitation of a previously unknown vulnerability in the web user interface feature of Cisco IOS XE Software when exposed to the internet or to untrusted networks. This vulnerability allows a remote, unauthenticated threat actor to create an account on a vulnerable system with privilege level 15 access. The threat actor could then potentially use that account to gain control of the affected system. Rockwell Automation is aware of active exploitation of a previously unknown vulnerability in the Web UI feature of Cisco IOS XE Software when exposed to the internet or to untrusted networks. This vulnerability could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-297-01</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2658 — Cisco IOS XE: Schwachstellen ermöglichten Administrativen Zugriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2658</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Cisco IOS XE ausnutzen, um Administrativen Zugriff zu erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Cisco IOS XE ausnutzen, um Administrativen Zugriff zu erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2658</guid>
    </item>
  </channel>
</rss>
