CVE-2023-20198

Vulnerability updated 5 months ago (2024-05-04T20:51:54.193Z)
Download STIX
Preview STIX
CVE-2023-20198 is a critical zero-day vulnerability found in the Web User Interface (Web UI) feature of Cisco IOS XE software. It was discovered when Cisco identified an active exploitation campaign that targeted this previously undisclosed flaw, enabling threat actors to create administrative accounts and install malicious implants on IOS XE devices. The vulnerability was exposed to the internet or untrusted networks, leading to thousands of IOS XE devices being compromised, as warned by security firm VulnCheck. The exploitation of CVE-2023-20198, along with another vulnerability CVE-2023-20273, was part of a larger campaign that saw tens of thousands of IOS XE devices compromised over a single week. This attack wave occurred in October, marking a shift in tactics for threat actors who had initially been compromising networks through poorly secured implementations of Windows RDP (remote desktop protocol) and stolen credentials. However, towards the end of the year, they increasingly exploited the vulnerability in devices running Cisco Systems’ IOS XE operating system. In response to these exploits, Cisco has taken action to address and rectify the vulnerabilities. A security advisory was released detailing the vulnerability and its potential impact, while patches were provided to fix both CVE-2023-20198 and CVE-2023-20273. This swift response followed the alarming discovery of the two zero-day vulnerabilities being used to compromise over 50,000 IOS XE devices within a single week. Despite these measures, organizations are urged to ensure their systems are updated and properly secured against potential future attacks.
Description last updated: 2024-03-17T13:16:47.658Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Cisco
Ios
Vulnerability
Exploit
CISA
Zero Day
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Vulnerabilities
To see the evidence that has resulted in these vulnerability associations, create a free account
Alias DescriptionAssociation TypeVotes
The CVE-2023-20273 Vulnerability is associated with CVE-2023-20198. CVE-2023-20273 is a high-severity zero-day vulnerability disclosed by Cisco on October 21, 2023. This flaw in software design or implementation was actively exploited to deploy malicious implants on IOS XE devices. The exploitation of this vulnerability was discovered during the investigation of anois related to
2
Source Document References
Information about the CVE-2023-20198 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
2 months ago
Securityaffairs
2 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
5 months ago
Securityaffairs
5 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
7 months ago
Securityaffairs
8 months ago
CERT-EU
8 months ago