This content is restricted.
Brief
Summary
A vulnerability has been identified in Rockwell Automation's Stratix 5800 and Stratix 5200 products, which run Cisco IOS XE Software with the Web UI feature enabled. The vulnerability, assigned CVE-2023-20198, allows an unauthenticated attacker to create an account with privilege level 15 access and potentially gain control of the affected system. The vulnerability has a CVSS v3 base score of 10.0 and is exploitable remotely with low attack complexity. Rockwell Automation recommends disabling the HTTP server feature, using more secure access methods, and implementing other defensive measures to minimize the risk of exploitation.
Highlights content goes here...
This content is restricted.
