What is
Cisco IOS XE Web UI?
Cisco IOS XE is the internetworking operating system used by the Next-Generation Cisco Systems such routers and switches. The Web UI provides deployment and manageability of these devices.
What is the
Attack?
A newly identified vulnerability on the Web UI of the Cisco IOS XE is exploited in the wild. The vulnerability is a privilege escalation tracked under CVE-2023-20198. This allows a remote, unauthenticated attacker to create an account on an affected system. The attacker can then use that account to gain control of the affected system. After exploiting that vulnerability, the attack can install a backdoor to the device and further infiltrate the network.
Why is this
Significant?
This vulnerability has been given the maximum security CVSS rating of 10.0. According to several security news articles, thousands of publicly exposed devices have already been compromised. Also, CISA has released an advisory for this attack.
https://www.cisa.gov/news-events/alerts/2023/10/16/cisco-releases-security-advisory-ios-xe-software-web-ui
What is theVendor Solution?
There is no workaround and patches available as of October 19, 2023.
What FortiGuard Coverage is available?
FortiGuard is currently developing a solution for protection against this vulnerability.
More Stories
USN-7015-1: Python vulnerabilities
It was discovered that the Python email module incorrectly parsed email addresses that contain special characters. A remote attacker could...
USN-7014-1: nginx vulnerability
It was discovered that the nginx ngx_http_mp4 module incorrectly handled certain malformed mp4 files. In environments where the mp4 directive...
USN-7013-1: Dovecot vulnerabilities
It was discovered that Dovecot incorrectly handled a large number of address headers. A remote attacker could possibly use this...
USN-7012-1: curl vulnerability
Hiroki Kurosawa discovered that curl incorrectly handled certain OCSP responses. This could result in bad certificates not being checked properly,...
USN-7011-1: ClamAV vulnerabilities
It was discovered that ClamAV incorrectly handled certain PDF files. A remote attacker could possibly use this issue to cause...
USN-6560-3: OpenSSH vulnerability
USN-6560-2 fixed a vulnerability in OpenSSH. This update provides the corresponding update for Ubuntu 16.04 LTS. Original advisory details: It...