CISA KEV · catalog date Oct 23, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-20273
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root.
Exploited in the wild (CISA KEV since Oct 23, 2023). NVD reports CVSS 3.1 7.2. EPSS estimates 89.6% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
- State
- PUBLISHED
- Published
- Oct 24, 2023
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAciscoOriginal evidence ↗
Record text: A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
Inspect raw assertion
- Field
container- Value
- A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Cisco IOS XE Web UI Command Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Cisco IOS XE Web UI Command Injection Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 89.63% probability · 99.78th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.896340000000; percentile 0.997760000000
FIRST EPSS · score date Aug 27, 2026 · 99.8th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
Inspect raw assertion
- Field
container- Value
- A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Cisco IOS XE Web UI Command Injection Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Cisco IOS XE Web UI Command Injection Vulnerability
89.63% probability · 99.78th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.896340000000; percentile 0.997760000000
Applicability
Cited product scope
Grouped from 4 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
125 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "16.1.1"}, {"status": "affected", "version": "16.1.2"}, {"status": "affected", "version": "16.1.3"}, {"status": "affected", "version": "16.2.1"}, {"status": "affected", "version": "16.2.2"}, {"status": "affected", "version": "16.3.1"}, {"status": "affected", "version": "16.3.2"}, {"status": "affected", "version": "16.3.3"}, {"status": "affected", "version": "16.3.1a"}, {"status": "affected", "version": "16.3.4"}, {"status": "affected", "version": "16.3.5"}, {"status": "affected", "version": "16.3.5b"}, {"status": "affected", "version": "16.3.6"}, {"status": "affected", "version": "16.3.7"}, {"status": "affected", "version": "16.3.8"}, {"status": "affected", "version": "16.3.9"}, {"status": "affected", "version": "16.3.10"}, {"status": "affected", "version": "16.3.11"}, {"status": "affected", "version": "16.4.1"}, {"status": "affected", "version": "16.4.2"}, {"status": "affected", "version": "16.4.3"}, {"status": "affected", "version": "16.5.1"}, {"status": "affected", "version": "16.5.1a"}, {"status": "affected", "version": "16.5.1b"}, {"status": "affected", "version": "16.5.2"}, {"status": "affected", "version": "16.5.3"}, {"status": "affected", "version": "16.6.1"}, {"status": "affected", "version": "16.6.2"}, {"status": "affected", "version": "16.6.3"}, {"status": "affected", "version": "16.6.4"}, {"status": "affected", "version": "16.6.5"}, {"status": "affected", "version": "16.6.4a"}, {"status": "affected", "version": "16.6.5a"}, {"status": "affected", "version": "16.6.6"}, {"status": "affected", "version": "16.6.7"}, {"status": "affected", "version": "16.6.8"}, {"status": "affected", "version": "16.6.9"}, {"status": "affected", "version": "16.6.10"}, {"status": "affected", "version": "16.7.1"}, {"status": "affected", "version": "16.7.1a"}, {"status": "affected", "version": "16.7.1b"}, {"status": "affected", "version": "16.7.2"}, {"status": "affected", "version": "16.7.3"}, {"status": "affected", "version": "16.7.4"}, {"status": "affected", "version": "16.8.1"}, {"status": "affected", "version": "16.8.1a"}, {"status": "affected", "version": "16.8.1b"}, {"status": "affected", "version": "16.8.1s"}, {"status": "affected", "version": "16.8.1c"}, {"status": "affected", "version": "16.8.1d"}, {"status": "affected", "version": "16.8.2"}, {"status": "affected", "version": "16.8.1e"}, {"status": "affected", "version": "16.8.3"}, {"status": "affected", "version": "16.9.1"}, {"status": "affected", "version": "16.9.2"}, {"status": "affected", "version": "16.9.1a"}, {"status": "affected", "version": "16.9.1b"}, {"status": "affected", "version": "16.9.1s"}, {"status": "affected", "version": "16.9.3"}, {"status": "affected", "version": "16.9.4"}, {"status": "affected", "version": "16.9.3a"}, {"status": "affected", "version": "16.9.5"}, {"status": "affected", "version": "16.9.5f"}, {"status": "affected", "version": "16.9.6"}, {"status": "affected", "version": "16.9.7"}, {"status": "affected", "version": "16.9.8"}, {"status": "affected", "version": "16.10.1"}, {"status": "affected", "version": "16.10.1a"}, {"status": "affected", "version": "16.10.1b"}, {"status": "affected", "version": "16.10.1s"}, {"status": "affected", "version": "16.10.1c"}, {"status": "affected", "version": "16.10.1e"}, {"status": "affected", "version": "16.10.1d"}, {"status": "affected", "version": "16.10.2"}, {"status": "affected", "version": "16.10.1f"}, {"status": "affected", "version": "16.10.1g"}, {"status": "affected", "version": "16.10.3"}, {"status": "affected", "version": "16.11.1"}, {"status": "affected", "version": "16.11.1a"}, {"status": "affected", "version": "16.11.1b"}, {"status": "affected", "version": "16.11.2"}, {"status": "affected", "version": "16.11.1s"}, {"status": "affected", "version": "16.12.1"}, {"status": "affected", "version": "16.12.1s"}, {"status": "affected", "version": "16.12.1a"}, {"status": "affected", "version": "16.12.1c"}, {"status": "affected", "version": "16.12.1w"}, {"status": "affected", "version": "16.12.2"}, {"status": "affected", "version": "16.12.1y"}, {"status": "affected", "version": "16.12.2a"}, {"status": "affected", "version": "16.12.3"}, {"status": "affected", "version": "16.12.8"}, {"status": "affected", "version": "16.12.2s"}, {"status": "affected", "version": "16.12.1x"}, {"status": "affected", "version": "16.12.1t"}, {"status": "affected", "version": "16.12.4"}, {"status": "affected", "version": "16.12.3s"}, {"status": "affected", "version": "16.12.3a"}, {"status": "affected", "version": "16.12.4a"}, {"status": "affected", "version": "16.12.5"}, {"status": "affected", "version": "16.12.6"}, {"status": "affected", "version": "16.12.1z1"}, {"status": "affected", "version": "16.12.5a"}, {"status": "affected", "version": "16.12.5b"}, {"status": "affected", "version": "16.12.1z2"}, {"status": "affected", "version": "16.12.6a"}, {"status": "affected", "version": "16.12.7"}, {"status": "affected", "version": "16.12.9"}, {"status": "affected", "version": "16.12.10"}, {"status": "affected", "version": "17.1.1"}, {"status": "affected", "version": "17.1.1a"}, {"status": "affected", "version": "17.1.1s"}, {"status": "affected", "version": "17.1.1t"}, {"status": "affected", "version": "17.1.3"}, {"status": "affected", "version": "17.2.1"}, {"status": "affected", "version": "17.2.1r"}, {"status": "affected", "version": "17.2.1a"}, {"status": "affected", "version": "17.2.1v"}, {"status": "affected", "version": "17.2.2"}, {"status": "affected", "version": "17.2.3"}, {"status": "affected", "version": "17.3.1"}, {"status": "affected", "version": "17.3.2"}, {"status": "affected", "version": "17.3.3"}, {"status": "affected", "version": "17.3.1a"}, {"status": "affected", "version": "17.3.1w"}, {"status": "affected", "version": "17.3.2a"}, {"status": "affected", "version": "17.3.1x"}, {"status": "affected", "version": "17.3.1z"}, {"status": "affected", "version": "17.3.4"}, {"status": "affected", "version": "17.3.5"}, {"status": "affected", "version": "17.3.4a"}, {"status": "affected", "version": "17.3.6"}, {"status": "affected", "version": "17.3.4b"}, {"status": "affected", "version": "17.3.4c"}, {"status": "affected", "version": "17.3.5a"}, {"status": "affected", "version": "17.3.5b"}, {"status": "affected", "version": "17.3.7"}, {"status": "affected", "version": "17.3.8"}, {"status": "affected", "version": "17.4.1"}, {"status": "affected", "version": "17.4.2"}, {"status": "affected", "version": "17.4.1a"}, {"status": "affected", "version": "17.4.1b"}, {"status": "affected", "version": "17.4.2a"}, {"status": "affected", "version": "17.5.1"}, {"status": "affected", "version": "17.5.1a"}, {"status": "affected", "version": "17.5.1b"}, {"status": "affected", "version": "17.5.1c"}, {"status": "affected", "version": "17.6.1"}, {"status": "affected", "version": "17.6.2"}, {"status": "affected", "version": "17.6.1w"}, {"status": "affected", "version": "17.6.1a"}, {"status": "affected", "version": "17.6.1x"}, {"status": "affected", "version": "17.6.3"}, {"status": "affected", "version": "17.6.1y"}, {"status": "affected", "version": "17.6.1z"}, {"status": "affected", "version": "17.6.3a"}, {"status": "affected", "version": "17.6.4"}, {"status": "affected", "version": "17.6.1z1"}, {"status": "affected", "version": "17.6.5"}, {"status": "affected", "version": "17.6.6"}, {"status": "affected", "version": "17.7.1"}, {"status": "affected", "version": "17.7.1a"}, {"status": "affected", "version": "17.7.1b"}, {"status": "affected", "version": "17.7.2"}, {"status": "affected", "version": "17.10.1"}, {"status": "affected", "version": "17.10.1a"}, {"status": "affected", "version": "17.10.1b"}, {"status": "affected", "version": "17.8.1"}, {"status": "affected", "version": "17.8.1a"}, {"status": "affected", "version": "17.9.1"}, {"status": "affected", "version": "17.9.1w"}, {"status": "affected", "version": "17.9.2"}, {"status": "affected", "version": "17.9.1a"}, {"status": "affected", "version": "17.9.1x"}, {"status": "affected", "version": "17.9.1y"}, {"status": "affected", "version": "17.9.3"}, {"status": "affected", "version": "17.9.2a"}, {"status": "affected", "version": "17.9.1x1"}, {"status": "affected", "version": "17.9.3a"}, {"status": "affected", "version": "17.9.4"}, {"status": "affected", "version": "17.9.1y1"}, {"status": "affected", "version": "17.11.1"}, {"status": "affected", "version": "17.11.1a"}, {"status": "affected", "version": "17.12.1"}, {"status": "affected", "version": "17.12.1a"}, {"status": "affected", "version": "17.11.99SW"}]product-362266000e9c23528223400dc4688b0735a8358bcab0f55152f834693adcab15Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7814fa61-caf1-46de-9d84-cebe6480ea03
product-25aa784ee66f3db180c03b8d3d5f45dd2db71e20dd1c18cf2cc48ff240225c1cLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48fd-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7ee4f60e-df3d-4839-8731-7cf16da8ff26
product-3a8d0c4044391b8bf095494353ca10d42a1272f081afe27772d143dcc0af1f9bLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48fd-l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8ea5eee3-a084-46b4-84c0-adfd69800649
product-a2b735339e7eb23fa1ee162253165a274feaa85fc21f0d8d4ddef200b619b293Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48fd-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
592f67d5-344b-49af-a277-1089a40ac2fd
product-6190f103761ae535d805136cea8a0884609e8de21fb5f29654668664eac9859aLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48uq:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7434059a-25b8-4fac-a756-6e571348b76e
product-9ed01461cd8a229a0925ea7f78b1f1e759329a47d0cdea79849a432eac4797bdLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48uq-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
db2a5355-bf40-437c-8683-a7a81dee362c
product-25abb086f008c35559114d436f0faffadffcc0de53e225dd0327c4827dd85c35Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48uq-l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
43f4b90e-3499-45d4-864d-18505e2149f2
product-62f13095f04c50cb267eab34a0fc138148e74f0568a6cf6a245992bdf1f97f08Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48uq-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1b9be6ba-6b2d-47c9-b8f1-3c9ce213948d
product-f83562b94b2cd239d39a0260e4a8f5881840d359229653a6ba3aa7900fc3c3a1Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48ur:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
858feecf-cc69-4e68-8e8a-674643021964
product-7614d44b42da7655aed2badae9e718bb2bd32d7cce690f75abe7f72b65edf982Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48ur-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
be5fccff-e491-474f-9b86-ab51d8244582
product-c459cd067c19c019841782c441ba4ddbff8a73d7abff514171fa0aaba64f9bb0Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48ur-l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ea8464f8-d6d2-4165-ade8-b40f7d8556c2
product-f687f50d408809a64bbda08133e4a665592aaa8aece49ffedfe85aea50f164bdLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48ur-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
61007628-a81b-43e0-86de-1f7ddad9f1a7
product-517166a6629a0613d68c19debfad26312f14b0a8ea20b6e8536a795af49970aaLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48uz:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
91b9f022-4c3d-493e-9418-e9cddafec9b1
product-1b814033910158ad411ecda4657673efac29ca2f4c829eb4313ab04d4cd66b95Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48uz-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2c3f03c3-c0ca-4e9b-a99a-be28153eb5c9
product-dfe09c382b51459e831894c0830f453ad412bfbfefdd9c665297f95795e7c81cLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48uz-l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b39f250e-6a89-4537-bd31-1fb81734a9a1
product-7d5729b3d8dfa78069de6a87c0c8bc46b9c040a151e09ce0a94298e51957f912Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-12x48uz-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cb4e3b69-dde8-4ea2-8e63-d6eef41083b3
product-cc440463cfcb1cf2f353fd7e136bcb48f98405143b5c3e2f2236990390f0399eLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-24pd:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8904eaf5-25e7-4a6b-8117-1859f913b83b
product-40e2f9cdacece2b0f743d68ee93cf7df7425e23cf159ffb16ef42ad735fcdc9fLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-24pd-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a369cd35-1242-4556-a83d-bd69cc149cfa
product-0c49f5666e333e8853d5c0e8a5ff12ecbb09e32d9dbd1e7c172f11e30098fcfdLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-24pd-l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aa2d1b9e-6234-4fd6-a003-afbc8a4dc2e6
product-25fc1311d6f9552aa42e81f4472fe51242b7b67e82f5af04b92b13fb31246c9aLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-24pdm:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
59a990d6-b748-4afd-b924-1d19680bd3db
product-b94f340dd3d4f8312358e28895fa8a1d76314ce41fad536af001be6dd9f4b974Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-24pdm-e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cecfc88d-5480-46e4-bf74-e11a514a8bdd
product-216bc6a63e3571b72b87249067aaa7e6cef26aae7f813091e29ffca0f43fc418Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-24pdm-l:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e54d16a8-0407-41e3-9599-9a6f57e1aa75
product-cb5751dbe215b30043a2d45d454a71306741aecccd8a85fb9545c4c9ccab0f09Linked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-24pdm-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c94a9a21-c4f7-4ea4-95b1-dea7dda0f77d
product-5998e08bba44f7240d8cab4cfe9b9108163d5a870823d410098bf19debf61e3dLinked exactInspect raw assertion
cpe:2.3:h:cisco:catalyst_3650-24pd-s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
784a1499-1f33-493d-b433-eb2550c03c19
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.