Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-20198 — Cisco IOS XE Auth bypass #18496

Closed
jvoisin opened this issue Oct 30, 2023 · 1 comment
Closed

CVE-2023-20198 — Cisco IOS XE Auth bypass #18496

jvoisin opened this issue Oct 30, 2023 · 1 comment
Labels
suggestion-module New module suggestions

Comments

@jvoisin
Copy link
Contributor

jvoisin commented Oct 30, 2023

Summary

Cisco IOS XE Authentication bypass

Basic example

https://www.horizon3.ai/cisco-ios-xe-cve-2023-20198-deep-dive-and-poc/

Motivation

Everyone and their dog is running this stuff. Moreover, the exploit is a single http request, so writing a module for it shouldn't be horrible.

@jvoisin jvoisin added the suggestion-module New module suggestions label Oct 30, 2023
@jvoisin jvoisin changed the title CVE-2023-20198 — Cisco IOS XE RCE CVE-2023-20198 — Cisco IOS XE Auth bypass Oct 30, 2023
@sfewer-r7
Copy link
Contributor

sfewer-r7 commented Nov 3, 2023

Added in pull request #18507

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
suggestion-module New module suggestions
Projects
None yet
Development

No branches or pull requests

3 participants