Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: 10,000 Cisco network devices backdoored through unpatched 0-day  (Read 2700 times)

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5285
    • Thinkbroadband Quality Monitors
10,000 Cisco network devices backdoored through unpatched 0-day
« on: October 24, 2023, 03:26:56 AM »

Meant to post this last week.

https://arstechnica.com/security/2023/10/actively-exploited-cisco-0-day-with-maximum-10-severity-gives-full-network-control/

Quote
The previously unknown vulnerability, which is tracked as CVE-2023-20198, carries the maximum severity rating of 10. It resides in the Web User Interface of Cisco IOS XE software when exposed to the Internet or untrusted networks. Any switch, router, or wireless LAN controller running IOS XE that has the HTTP or HTTPS Server feature enabled and exposed to the Internet is vulnerable. On Monday, the Shodan search engine showed that as many as 80,000 Internet-connected devices could be affected.

Although quite why any of these devices would have the web UI exposed to the Internet to begin with is beyond me.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

dee.jay

  • Helpful
  • Reg Member
  • *
  • Posts: 985
Re: 10,000 Cisco network devices backdoored through unpatched 0-day
« Reply #1 on: October 24, 2023, 07:56:30 AM »

Quote
Any switch, router, or wireless LAN controller running IOS XE that has the HTTP or HTTPS Server feature enabled and exposed to the Internet is vulnerable.

From looking at the documentation: - (https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/https/configuration/xe-17/https-xe-17-book/HTTP_1-1_Web_Server_and_Client.html)

Quote
The HTTP/HTTPS server is disabled by default.

Most engineers worth their salt would leave it that way, too.
Logged
AAISP 1000/115 FTTP routed by opnsense on proxmox. Even my WiFi is baller

XGS_Is_On

  • Reg Member
  • ***
  • Posts: 479
Re: 10,000 Cisco network devices backdoored through unpatched 0-day
« Reply #2 on: October 24, 2023, 01:40:05 PM »

Nothing wrong with using a GUI if it's convenient and appropriate :)

Having that GUI reachable from untrusted sources not so much.
Logged
YouFibre You8000 customer: symmetrical 8 Gbps.

Yes, more money than sense. Story of my life.
 

anything