Cisco, a network hardware provider, issues a warning after discovering a serious zero-day vulnerability in the web user interface (UI) of its IOS XE software.Â
The vulnerability is tracked as CVE-2023-20198, and can be exploited when exposed to public internet or untrusted networks. This enables remote, unauthenticated attackers to establish accounts with all privileges, which are used to take control of affected systems.Â
The firm says that affected customers are those who have enabled the web UI feature through the ‘ip http server’ or ‘ip http secure-server’ commands. Cisco provided instructions for users to determine whether they were affected by the vulnerability.
In response to this threat, Cisco is strongly recommending that customers disable the HTTP Server feature on all internet-facing systems. This can be achieved by using the “no ip http server” or “no ip http secure-server” command in global configuration mode.Â
If both the HTTP server and HTTPS server are in use, both commands must be executed to disable the HTTP Server feature. However, Cisco advises users to exercise caution when restricting access controls, as it could lead to a broader service interruption.
Cisco is actively working on a patch for the vulnerability, which is expected to impact a significant number of users. The issue came to light when the research team at Cisco Talos, in collaboration with Cisco’s Technical Assistance Centre (TAC), detected the vulnerability on 28 September.Â
Further investigation revealed that the vulnerability may have been exploited up to 10 days prior to its discovery. In one instance, an authorized user created a local user account from a suspicious IP address.
Recommended
- First Ever Global Drone Standards Unveiled
- Is Scotland’s Public Sector Failing on HTTPS Encryption?
- Zero-day Vulnerability Found in iOS: Update Your iPhone Now
Subsequently, on 12 October, Talos and TAC detected new, related activity when an unauthorized user created a local user account with full admin rights, suggesting that adequate attention to patching had not been given.Â
This user carried out several actions, including deploying an implant file, potentially delivered via the long-patched CVE-2021-1435 vulnerability.
The implant includes a configuration file that defines a new web server endpoint for interacting with the implant, allowing the intruder to execute arbitrary commands at the system or IOS level.Â
While the implant is not persistent and can be removed with a device reboot, the newly-created user accounts remain active with full admin rights. Cisco and its users are urged to remain vigilant and apply the upcoming patch once available.





