Skip to content

security_identifier

CVE-2023-20273

The second of two IOS XE Web UI flaws Cisco disclosed together with CVE-2023-20198; the shared advisory was last revised 1 November 2023.

Current clusters

security1 publisher

Salt Typhoon logged into telecom network gear with stolen credentials in all but one case Talos examined

Salt Typhoon used legitimate stolen credentials to reach Cisco devices in every telecom intrusion Cisco Talos investigated but one. It then pulled more logins from weakly encrypted router configs and captured TACACS and RADIUS keys, so credentials stored on network gear are the first exposure for defenders to close.

Reality

Evidence62
Adoption
Insufficient
Hype gap−5
Incentives55
Confidence60