VORANT. Threat Intelligence Sign in Get the full feed

Cisco IOS XE web UI flaw exploited

critical vulnerability telecommunicationsgovernment-nationaltechnology

A privilege-escalation vulnerability in Cisco IOS XE's web UI is being actively exploited to create rogue admin accounts and take over devices.

IPA (Japan's Information-technology Promotion Agency) issued an alert regarding a privilege escalation vulnerability in Cisco IOS XE, the operating system used across Cisco's networking equipment. The flaw allows a remote, unauthenticated attacker to create a highest-privilege account on the affected system, potentially granting full control of the device.

The advisory states that exploitation of this vulnerability has already been observed in the wild, prompting IPA to urge organizations to apply vendor-provided fixes, follow recommended mitigations, and investigate systems for signs of compromise as soon as possible. Cisco has published guidance on detecting exploitation and post-compromise indicators, which IPA directs readers to consult directly. The alert was updated on November 2, 2023, to expand the list of affected systems and add patched version information.

Mentioned in this report

Vulnerabilities CVE-2023-20198KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/alert20231023-1.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free