Skip to content

[FALSE-NEGATIVE] CVE-2023-20198 Cisco IOS XE RCE #12324

@sh00bx

Description

@sh00bx

Template IDs or paths

http/cves/2023/CVE-2023-20198.yaml

Environment

- OS: Ubuntu 22.04
- Nuclei: v3.4.4
- Go: 1.23.0

Steps To Reproduce

  1. Run template against CVE-2023-20198 vulnerable target on https
  2. False negative

The issue is most likely caused by the target endpoint on Cisco differing depending whether access is via http or https. I could achieve detection by modifying the target endpoint on the template to /%2577ebui_wsma_https

Relevant dumped responses

no detection (details below)

Anything else?

Image

post endpoint modification:

Image

Metadata

Metadata

Assignees

Labels

false-negativeNuclei template missing valid results

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions