CVE-2023-20198
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
18 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.01%
probability
This CVE has a 94.01% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
smokeintheshell/CVE-2023-20198
CVE-2023-20198 Exploit PoC
64
W01fh4cker/CVE-2023-20198-RCE
CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.
42
fox-it/cisco-ios-xe-implant-detection
Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)
41
ZephrFish/CVE-2023-20198-Checker
CVE-2023-20198 & 0Day Implant Scanner
33
Shadow0ps/CVE-2023-20198-Scanner
This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273
33
Atea-Redteam/CVE-2023-20198
CVE-2023-20198 Checkscript
20
Tounsi007/CVE-2023-20198
CVE-2023-20198 PoC (!)
11
Pushkarup/CVE-2023-20198
A PoC for CVE 2023-20198
8
RevoltSecurities/CVE-2023-20198
An Exploitation script developed to exploit the CVE-2023-20198 Cisco zero day vulnerability on their IOS routers
7
iveresk/cve-2023-20198
1vere$k POC on the CVE-2023-20198
6
10 repos — triés par ⭐
Rechercher sur GitHub ↗
Defense Lessons From the Black Basta Ransomware Playbook
Qualys
Feb 25, 2025
Exploit released for critical Cisco IOS XE flaw, many hosts still hacked
BleepingComputer
Oct 30, 2023
Cisco warns of new IOS XE zero-day actively exploited in attacks
BleepingComputer
Oct 16, 2023
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
ASD Warns of Ongoing BADCANDY Attacks Exploiting Cisco IOS XE Vulnerability
TheHackerNews
Nov 01, 2025
Cisco discloses new IOS XE zero-day exploited to deploy malware implant
BleepingComputer
Oct 20, 2023
Over 10,000 Cisco devices hacked in IOS XE zero-day attacks
BleepingComputer
Oct 17, 2023
Cisco patches IOS XE zero-days used to hack over 50,000 devices
BleepingComputer
Oct 23, 2023
Over 40,000 Cisco IOS XE devices infected with backdoor using zero-day
BleepingComputer
Oct 19, 2023
Hackers update Cisco IOS XE backdoor to hide infected devices
BleepingComputer
Oct 22, 2023
Security Advisory 2023-078
CERT-EU
Oct 23, 2023
[MàJ] Multiples vulnérabilités dans Cisco IOS XE (17 octobre 2023)
CERT-FR
Oct 17, 2023
Signal Intelligence
Confidence
92%
EPSS
94.01%
Mentions
18
Last Seen
May 27, 2026
CNA Information
Analyst Note
CVE-2023-20198 explicitly identified as exploited in the wild via BADCANDY attacks against unpatched Cisco IOS XE devices, with Cisco's official advisory confirming 'previously unknown' exploitation occurring before patches were available. Exploitation timing aligns with CVE publication in October 2023 and active attacks documented by ASD.
Threat Actors 40
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
APT 41
apt_group
Information theft and espionage
🇨🇳 CN
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
APT27
apt_group
Information theft and espionage
🇨🇳 CN
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT37
apt_group
Information theft and espionage
🇰🇵 KP
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
FIN7
apt_group
Financial crime
🇷🇺 RU
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Harvester
apt_group
Information theft and espionage
Unknown
Leviathan
apt_group
Information theft and espionage
🇨🇳 CN
Hacking Team
apt_group
🇮🇹 IT
GhostEmperor
apt_group
Information theft and espionage
🇨🇳 CN
UAC-0020
apt_group
🇺🇦 UA
APT3
apt_group
Information theft and espionage
🇨🇳 CN
AridViper
apt_group
Information theft and espionage
🇵🇸 PS
Infy
apt_group
Information theft and espionage
🇮🇷 IR
SideWinder
apt_group
🇮🇳 IN
RAZOR TIGER
apt_group
Information theft and espionage
🇮🇳 IN
FamousSparrow
apt_group
Information theft and espionage
🇨🇳 CN
Larva-208
apt_group
🇷🇺 RU
Earth Estries
apt_group
Information theft and espionage
🇨🇳 CN
APT31
apt_group
Information theft and espionage
🇨🇳 CN
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
RedGolf
apt_group
Information theft and espionage
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
Markopolo
apt_group
🇷🇺 RU
Storm-0324
apt_group
Red Dev 17
apt_group
🇨🇳 CN
Red October
apt_group
🇷🇺 RU
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Higaisa
apt_group
🇰🇷 KR
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
LightBasin
apt_group
Information theft and espionage
🇨🇳 CN
Operation Black Atlas
apt_group
Financial crime
Dark Partners
apt_group
Triage Info
Decided atMar 05, 2026