What is
Cisco IOS XE Web UI?
Cisco IOS XE is the internetworking operating system used by the Next-Generation Cisco Systems such routers and switches. The Web UI provides deployment and manageability of these devices.
What is the
Attack?
A newly identified vulnerability on the Web UI of the Cisco IOS XE is exploited in the wild. The vulnerability is a privilege escalation tracked under CVE-2023-20198. This allows a remote, unauthenticated attacker to create an account on an affected system. The attacker can then use that account to gain control of the affected system. After exploiting that vulnerability, the attack can install a backdoor to the device and further infiltrate the network.
Why is this
Significant?
This vulnerability has been given the maximum security CVSS rating of 10.0. According to several security news articles, thousands of publicly exposed devices have already been compromised. Also, CISA has released an advisory for this attack.
https://www.cisa.gov/news-events/alerts/2023/10/16/cisco-releases-security-advisory-ios-xe-software-web-ui
What is theVendor Solution?
There is no workaround and patches available as of October 19, 2023.
What FortiGuard Coverage is available?
FortiGuard is currently developing a solution for protection against this vulnerability.
More Stories
kernel-6.6.3-200.fc39 kernel-headers-6.6.3-200.fc39 kernel-tools-6.6.3-200.fc39
FEDORA-2023-a7b89262c6 Packages in this update: kernel-6.6.3-200.fc39 kernel-headers-6.6.3-200.fc39 kernel-tools-6.6.3-200.fc39 Update description: The 6.6.3 stable kernel update contains a number of important...
kernel-6.6.3-100.fc38 kernel-headers-6.6.3-100.fc38 kernel-tools-6.6.3-100.fc38
FEDORA-2023-15deb2e32a Packages in this update: kernel-6.6.3-100.fc38 kernel-headers-6.6.3-100.fc38 kernel-tools-6.6.3-100.fc38 Update description: The 6.6.3 stable kernel update contains a number of important...
USN-6502-3: Linux kernel (NVIDIA) vulnerabilities
Ivan D Barrera, Christopher Bednarz, Mustafa Ismail, and Shiraz Saleem discovered that the InfiniBand RDMA driver in the Linux kernel...
USN-6520-1: Linux kernel (StarFive) vulnerabilities
Ivan D Barrera, Christopher Bednarz, Mustafa Ismail, and Shiraz Saleem discovered that the InfiniBand RDMA driver in the Linux kernel...
gmailctl-0.10.7-1.fc39
FEDORA-2023-e3e4e3f51a Packages in this update: gmailctl-0.10.7-1.fc39 Update description: upgrade to v0.10.7, CVE-2023-39325 Read More
gmailctl-0.10.7-1.fc38
FEDORA-2023-6f4c5b6331 Packages in this update: gmailctl-0.10.7-1.fc38 Update description: upgrade to v0.10.7, close rhbz#2249798 Read More