Cisco IOS XE zero-day bug exploited

Share post:

Cisco users have been advised to disable the web UI feature on all internet-facing devices immediately after the company disclosed a critical zero-day vulnerability in its IOS XE software that is being actively exploited in the wild.

The vulnerability, CVE-2023-20198, allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access, essentially giving them complete control of the device.

Cisco says the flaw affects physical and virtual devices running its IOS XE software, with the HTTP or HTTPS Server feature turned on. The networking giant hasn’t published a full list of devices that are at risk.

Also, there’s no patch or workaround. Hence, Cisco “strongly recommends” that customers disable this feature on all internet-facing systems. This also echoes guidance from the U.S. Cybersecurity and Infrastructure Security Agency on how to mitigate risk from internet-exposed management interfaces.

“To disable the HTTP Server feature, use the no ip http server or no ip http secure-server command in global configuration mode,” Cisco’s advisory recommends . “If both the HTTP server and HTTPS server are in use, both commands are required to disable the HTTP Server feature.”

The sources for this piece include an article in TheRegister.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways