{"id":42181,"date":"2023-10-18T08:55:07","date_gmt":"2023-10-18T12:55:07","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=42181"},"modified":"2023-10-19T10:28:16","modified_gmt":"2023-10-19T14:28:16","slug":"cisco-ios-xe-zero-day-bug-exploited","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/cisco-ios-xe-zero-day-bug-exploited\/","title":{"rendered":"Cisco IOS XE zero-day bug exploited"},"content":{"rendered":"<p data-ar-index=\"1\">Cisco users have been advised to disable the web UI feature on all internet-facing devices immediately after the company disclosed a critical zero-day vulnerability in its IOS XE software that is being actively exploited in the wild.<\/p>\n<p data-ar-index=\"2\">The vulnerability, CVE-2023-20198, allows a remote, unauthenticated attacker to create an account on an affected system with privilege level 15 access, essentially giving them complete control of the device.<\/p>\n<p data-ar-index=\"3\">Cisco says the flaw affects physical and virtual devices running its IOS XE software, with the HTTP or HTTPS Server feature turned on. The networking giant hasn&#8217;t published a full list of devices that are at risk.<\/p>\n<p data-ar-index=\"4\">Also, there&#8217;s no patch or workaround. Hence, Cisco &#8220;strongly recommends&#8221; that customers disable this feature on all internet-facing systems. This also echoes guidance from the U.S. Cybersecurity and Infrastructure Security Agency on how to mitigate risk from internet-exposed management interfaces.<\/p>\n<p data-ar-index=\"5\">&#8220;To disable the HTTP Server feature, use the no ip http server or no ip http secure-server command in global configuration mode,&#8221; Cisco\u2019s advisory recommends . &#8220;If both the HTTP server and HTTPS server are in use, both commands are required to disable the HTTP Server feature.&#8221;<\/p>\n<p data-ar-index=\"6\">The sources for this piece include an article in <a href=\"https:\/\/www.theregister.com\/2023\/10\/16\/cisco_ios_xe_zeroday_exploit\/?td=rt-3a\" target=\"_blank\" rel=\"noopener\">TheRegister<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco users have been advised to disable the web UI feature on all internet-facing devices immediately after the company disclosed a critical zero-day vulnerability in its IOS XE software that is being actively exploited in the wild. The vulnerability, CVE-2023-20198, allows a remote, unauthenticated attacker to create an account on an affected system with privilege [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16],"tags":[388],"class_list":["post-42181","post","type-post","status-publish","format-standard","hentry","category-security","tag-privacy-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/42181","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=42181"}],"version-history":[{"count":2,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/42181\/revisions"}],"predecessor-version":[{"id":42183,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/42181\/revisions\/42183"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=42181"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=42181"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=42181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}