CVE-2023-20198

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 18 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.01%
probability
This CVE has a 94.01% probability of being exploited in the next 30 days.
0% Top 99.9th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Attack Intelligence

Exploits & PoC

smokeintheshell/CVE-2023-20198

CVE-2023-20198 Exploit PoC

64
W01fh4cker/CVE-2023-20198-RCE

CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.

42
fox-it/cisco-ios-xe-implant-detection

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

41
ZephrFish/CVE-2023-20198-Checker

CVE-2023-20198 & 0Day Implant Scanner

33
Shadow0ps/CVE-2023-20198-Scanner

This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273

33
Atea-Redteam/CVE-2023-20198

CVE-2023-20198 Checkscript

20
Tounsi007/CVE-2023-20198

CVE-2023-20198 PoC (!)

11
Pushkarup/CVE-2023-20198

A PoC for CVE 2023-20198

8
RevoltSecurities/CVE-2023-20198

An Exploitation script developed to exploit the CVE-2023-20198 Cisco zero day vulnerability on their IOS routers

7
iveresk/cve-2023-20198

1vere$k POC on the CVE-2023-20198

6
10 repos — triés par ⭐ Rechercher sur GitHub ↗
Security Advisory 2023-078
CERT-EU Oct 23, 2023

Signal Intelligence

Confidence
92%
EPSS 94.01%
Mentions 18
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2023-20198 explicitly identified as exploited in the wild via BADCANDY attacks against unpatched Cisco IOS XE devices, with Cisco's official advisory confirming 'previously unknown' exploitation occurring before patches were available. Exploitation timing aligns with CVE publication in October 2023 and active attacks documented by ASD.

Threat Actors 40

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
APT 41
apt_group Information theft and espionage 🇨🇳 CN
APT 29
apt_group Information theft and espionage 🇷🇺 RU
APT27
apt_group Information theft and espionage 🇨🇳 CN
Cobalt
apt_group Financial crime 🇷🇺 RU
APT37
apt_group Information theft and espionage 🇰🇵 KP
APT 28
apt_group Information theft and espionage 🇷🇺 RU
FIN7
apt_group Financial crime 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Harvester
apt_group Information theft and espionage Unknown
Leviathan
apt_group Information theft and espionage 🇨🇳 CN
Hacking Team
apt_group 🇮🇹 IT
GhostEmperor
apt_group Information theft and espionage 🇨🇳 CN
UAC-0020
apt_group 🇺🇦 UA
APT3
apt_group Information theft and espionage 🇨🇳 CN
AridViper
apt_group Information theft and espionage 🇵🇸 PS
Infy
apt_group Information theft and espionage 🇮🇷 IR
SideWinder
apt_group 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
FamousSparrow
apt_group Information theft and espionage 🇨🇳 CN
Larva-208
apt_group 🇷🇺 RU
Earth Estries
apt_group Information theft and espionage 🇨🇳 CN
APT31
apt_group Information theft and espionage 🇨🇳 CN
APT 22
apt_group Information theft and espionage 🇨🇳 CN
RedGolf
apt_group Information theft and espionage 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Markopolo
apt_group 🇷🇺 RU
Storm-0324
apt_group
Red Dev 17
apt_group 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Operation Red Signature
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Higaisa
apt_group 🇰🇷 KR
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN
LightBasin
apt_group Information theft and espionage 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime
Dark Partners
apt_group

Triage Info

Decided atMar 05, 2026