Cisco IOS XE Web UI Exploitation Indicators for CVE-2023-20198 via Syslog Login and Config Events

Matches Cisco IOS XE Web UI and web login success logs consistent with CVE-2023-20198 exploitation using specified admin/TAC usernames.

FreeReviewedSigma · High · v5
Product
cisco
Service
syslog
Author
Lars B. P. Frydenskov (Trifork Security) (SigmaHQ), DRL 1.1
Published
2023-10-20
Updated
2026-07-31

What it detects

This rule flags likely exploitation activity for the Cisco IOS XE Web UI privilege escalation vulnerability by matching specific Cisco syslog messages combined with successful web login context. It focuses on events that include Web UI install operation information and configuration-related syslog entries alongside successful web logins for privileged Cisco-related accounts. The detection relies on Cisco IOS XE syslog telemetry where these message strings and usernames are present.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.