
"Cisco Exposes Actively Exploited Zero-Day Vulnerability in IOS XE"
Cisco has issued a warning about a new zero-day vulnerability, tracked as CVE-2023-20198, in its IOS XE Software that is being actively exploited by attackers. The vulnerability allows attackers to gain full administrator privileges and take control of affected routers. The exploit affects devices running with the Web User Interface (Web UI) feature enabled and the HTTP or HTTPS Server feature toggled on. Cisco advises disabling the HTTP server feature on internet-facing systems and recommends looking for unexplained or recently created user accounts as potential indicators of malicious activity. The company is working on a software fix and urges customers to take immediate action.