"Cisco Exposes Actively Exploited Zero-Day Vulnerability in IOS XE"

1 min read
Source: BleepingComputer
"Cisco Exposes Actively Exploited Zero-Day Vulnerability in IOS XE"
Photo: BleepingComputer
TL;DR Summary

Cisco has issued a warning about a new zero-day vulnerability, tracked as CVE-2023-20198, in its IOS XE Software that is being actively exploited by attackers. The vulnerability allows attackers to gain full administrator privileges and take control of affected routers. The exploit affects devices running with the Web User Interface (Web UI) feature enabled and the HTTP or HTTPS Server feature toggled on. Cisco advises disabling the HTTP server feature on internet-facing systems and recommends looking for unexplained or recently created user accounts as potential indicators of malicious activity. The company is working on a software fix and urges customers to take immediate action.

Share this article

Reading Insights

Total Reads

0

Unique Readers

10

Time Saved

2 min

vs 3 min read

Condensed

81%

561104 words

Want the full story? Read the original article

Read on BleepingComputer