Cisco identifies another IOS XE vulnerability, with patches coming this weekend
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-1435 | A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the ro A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the root user. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted request to the web UI of an affected device with arbitrary commands injected into a portion of the request. A successful exploit could allow the attacker to execute arbitrary commands as the root user. NVD description · AI analysis pending | 7.2 | 8% |
| — | ||
| CVE-2023-20198 | Unauthenticated Privilege Escalation in Cisco IOS XE Web UI (Actively Exploited) CVE-2023-20198 is a critical (CVSS 10.0) unauthenticated privilege escalation flaw in the web UI of Cisco IOS XE software, triggered by sending crafted network requests to the exposed web management interface. An attacker with no credentials can use the flaw to gain initial access and issue a privilege 15 command, creating a local user with normal login access; the attacker then chained CVE-2023-20273 (CVSS 7.2) to elevate that account to root and write an implant to the file system. Successful exploitation yields full administrative control of the device, including persistence via the planted implant, on Cisco IOS XE devices with the web UI enabled and reachable from the internet or untrusted networks, including Rockwell Automation Allen-Bradley Stratix 5200 and 5800 switches running IOS XE. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-16 with a BOD 23-02 directive, EPSS stands at 99.6% (100th percentile), and ongoing campaigns (including the 'BADCANDY' activity flagged by Australia's ASD and Cisco-related telecom intrusions attributed to Salt Typhoon) have been reported. Do: Upgrade affected devices to the fixed releases listed in Cisco's advisory (use Cisco's Software Checker) and, as immediate mitigation, disable the web UI or restrict it to trusted networks/addresses only. Check for compromise by looking for unexpected local user accounts and the implant artifacts Cisco identified (unexpected cisco_tac_alarm.log and cisco_tac.log files in /tmp or /usr/binos/conf), and immediately report positive findings to CISA per BOD 23-02. Keep in mind that patching alone does not remove a root implant, so devices with evidence of compromise should be reimaged or otherwise cleaned per vendor instructions. | 10.0 | 100% | KEV |
| large≈40,000–50,000 internet-exposed IOS XE devices at the time of disclosure (public scan data), within an IOS XE install base in the millions | |
| CVE-2023-20273 | Authenticated Command Injection (Root) in Cisco IOS XE Web UI CVE-2023-20273 is an OS command injection flaw (CWE-78) in the web UI feature of Cisco IOS XE Software, caused by insufficient input validation. An authenticated, remote attacker triggers it by sending crafted input to the web UI, and a successful exploit injects commands that run on the underlying operating system with root privileges, yielding full device compromise (in the October 2023 mass-exploitation campaign it was typically chained with the unauthenticated CVE-2023-20198 to obtain initial access and install a persistent implant). Any Cisco IOS XE device with the web UI enabled and reachable from the internet or an untrusted network is affected; this data does not specify the affected release ranges, which are enumerated in Cisco's advisory. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-10-23 with BOD 23-02 response actions, EPSS is ~90% (100th percentile), and IOS XE edge devices remain recurring targets of Chinese-nexus espionage campaigns (e.g., Salt Typhoon activity against telecoms). Do: Upgrade affected devices to a fixed IOS XE release per Cisco's advisory; as an interim mitigation, disable the HTTP/HTTPS server (ip http server / ip https server) or restrict Web UI access to trusted hosts only. Per BOD 23-02, hunt for compromise on any exposed device — check for unexpected level-15 local accounts and the implant.lua backdoor in flash memory — and immediately report positive findings to CISA. | 7.2 | 90% | KEV |
| mass≈100,000+ internet-exposed IOS XE devices (public scans observed ~40,000+ compromised within days of disclosure) |
Full article776 words · extracted from therecord.media · click to collapse
Cisco has identified a second issue connected to a popular software line after security experts raised concerns throughout the week about thousands of potential victims affected by a zero-day bug. Earlier this week, Cisco released an advisory and a detailed blog post about CVE-2023-20198 — warning defenders that it carries the highest severity CVSS score possible of 10 and was being exploited by hackers. A patch was not available to address the issue, and Cisco urged customers to make sure that affected devices were not accessible from the internet. In a statement to Recorded Future News on Friday, the tech giant said a patch would be available for the issue on Sunday. The company also addressed a specific issue raised in the blog that had caused alarm among experts. Cisco initially said that during attacks involving the vulnerability, their incident responders observed hackers also exploiting CVE-2021-1435, which Cisco had patched in 2021. Devices fully patched against that bug were seen infected by implants successfully installed “through an as of yet undetermined mechanism.” Cisco updated its advisory on CVE-2023-20198 to include a new vulnerability — tracked as CVE-2023-20273 — that addresses this specific issue. They updated the blog to explain that the patch coming on Sunday will address both bugs. They added that the CVE-2021-1435, the vulnerability patched in 2021, “is no longer assessed to be associated with this activity.” “On October 16 we published a security advisory informing customers about active exploitation of a previously unknown vulnerability, urging them to take immediate action to keep them safe. Through ongoing investigation, we uncovered the attacker combined two vulnerabilities to bypass security measures (the first for initial access and the second to elevate privilege once authenticated),” a spokesperson said. “We have now identified a fix that covers both vulnerabilities.”
The issue affects Cisco routers, switches, access points, wireless controllers and more. Josh Foster, technical manager at cyber defense company Horizon3.ai, told Recorded Future News that hackers exploiting the bug are able to monitor network traffic; eavesdrop on privileged network communications; inject and redirect network traffic; breach protected network segments, and use the compromised device as a “persistent beachhead to the network as there is a lack of detection/protection solutions for these devices and they can often go overlooked during patch-cycles until a disruption to user activity is noticed.” Foster outlined a range of short- and long-term options victims have for addressing the issue in a blog on Friday. The vulnerability, which grants an attacker full administrator privileges and allows them to effectively take full control of an affected router, left defenders scrambling all week. Several security companies said they found thousands of exposed and compromised devices online. Research firm Censys identified 41,983 infected hosts on October 18. That number had dropped to 36,541 by Thursday. VulnCheck published a scanner that can be used to find implanted systems on the internet. CERT Orange Cyberdefense said it found over 34,500 Cisco IOS XE IPs compromised by CVE-2023-20198 with implants. Another company, GreyNoise, confirmed that more than 40,000 Cisco IOS devices had their web admin interfaces exposed to the internet and fell victim to the latest round of implant attacks. “Cisco buried the lede by not mentioning thousands of internet-facing IOS XE systems have been implanted,” VulnCheck’s Jacob Baines said earlier this week “VulnCheck scanned internet-facing Cisco IOS XE web interfaces and found thousands of implanted hosts. This is a bad situation, as privileged access on the IOS XE likely allows attackers to monitor network traffic, pivot into protected networks, and perform any number of man-in-the-middle attacks.” Cisco said it has been observing attacks since September 28 and a spokesperson reiterated its advice that customers should disable the HTTP server feature on internet-facing devices while a patch is worked on. Experts with the cybersecurity company Rapid7 said they are currently responding to multiple incidents involving the vulnerability. The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its list of exploited bugs and gave federal civilian agencies until Friday to verify that instances of Cisco IOS XE Web UI are not exposed to the internet. CISA urged government agencies to “follow vendor instructions to determine if a system may have been compromised and immediately report positive findings to CISA.” Earlier this month, Cisco released an advisory of another vulnerability affecting the same software.36,541 compromises
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisco-ios-xe-vulnerability-patches-coming