Get the App
SLTechnology News&Howtos  ›  IT Information  › 

Cisco issued a security announcement: urging administrators to troubleshoot and mitigate vulnerabilities out of 10 points and zero days

Shulou Source: shulou.com Published: 2023-11-24 21:18:35 10月02日 Update

CTOnews.com, October 17 (Xinhua)-- Cisco issued a security announcement on Monday, urging network administrators to conduct self-inspection as soon as possible, recommending that HTTPS server features be disabled on Internet-facing systems.

CTOnews.com note, this vulnerability tracking number is CVE-2023-20198 and is rated as the highest severity level 10.0 on the CVSS rating system, which is a rare full-score vulnerability, and there is available evidence that hackers have exploited the vulnerability to launch attacks.

The flaw lies in IOS XE software, where switches, routers, or wireless LAN controllers with HTTP or HTTPS server enabled and exposed to Internet are vulnerable, and the Shodan search engine indicates that more than 80000 networked devices may be affected.

Cisco said the vulnerability was first discovered on Sept. 18, when a hacker successfully hacked into the device, created a local account after being authorized, and then deployed an implant that could execute malicious commands at the system level once the Web server restarted.

Tags: Vulnerabilities servers systems services Cisco features devices hackers attacks security announcements full scores administrators highest success next Internet switches commands rare Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Microsoft OPPO Reno Apple Huawei macOS