Loading HuntDB...

GHSA-4xrf-pcxr-rf3c

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

Cisco is aware of active exploitation of a previously unknown vulnerability in the web UI feature of Cisco IOS XE Software when exposed to the internet or to untrusted networks. This vulnerability allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access. The attacker can then use that account to gain control of the affected system.

For steps to close the attack vector for this vulnerability, see the Recommendations section of this advisory 

Cisco will provide updates on the status of this investigation and when a software patch is available.

Related CVEs

Key Information

GHSA ID
GHSA-4xrf-pcxr-rf3c
Published
October 16, 2023 6:30 PM
Last Modified
January 25, 2024 6:30 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.