Cyber Security News

Exploit Released for Cisco IOS XE Zero-day Vulnerability

Cisco was reported with a critical vulnerability last week, which has been actively exploited by threat actors in the wild. The vulnerability was assigned with the CVE-2023-20198 and was given a severity rating of 10.0 (Critical).

This particular vulnerability affects Cisco IOS XE software installed in thousands of Cisco devices, including routers, switches, and many other networking devices. However, Cisco has patched this vulnerability and has released a security advisory.

CVE-2023-20198: Authentication Bypass in Cisco IOS XE Web UI

This vulnerability exists in the Web UI of Cisco IOS Xe, which will allow an unauthenticated threat actor to elevate their privileges and create an account on an affected system with privilege level 15 access (Unlimited access). 

This new account will provide complete control over the device to the threat actor, after which arbitrary commands can be executed. The severity for this vulnerability has been given as 10.0 (Critical).

Exploit PoC

The threat actor must reach the webui_wsma_http or webui_wsma_https endpoints somehow as a prerequisite. Post this, they can craft a malicious POST request with the endpoint /%2577ebui_wsma_HTTP that bypasses the Nginx matches to reach the WMSA service in iosd.

Exploit HTTP request (Source: Horizon3)

The WSMA (Web Services Management Agent) also allows users to execute commands and configure the system through SOAP requests. Per Cisco’s documentation, SOAP requests can be used to access the configuration feature.

Furthermore, this service can also create a new user with privilege level 15 by sending the CLI command username <user> privilege 15 secret <password>. To confirm the exploitation, the Administration -> User Administration panel in the UI can be used to see the new user. 

A complete report about this proof-of-concept has been published by Horizon3, which provides detailed information about the exploit theory, method of exploitation, and other details.

To fix this vulnerability, Cisco has implemented a Proxy-Uri-Source header added in the patch, which prevents threat actors from accessing the WSMA service. The default header value has been set to global and to webui_internal for legitimate requests. 

Fixed in Release

Cisco IOS XE Software Release TrainFirst Fixed ReleaseAvailable
17.917.9.4aYes
17.617.6.6aYes
17.317.3.8aTBD
16.12 (Catalyst 3650 and 3850 only)16.12.10aYes

Source: Cisco

It is recommended that users of Cisco devices with Cisco IOS XE software upgrade to the latest version to prevent this vulnerability from getting exploited.

Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Try a free trial to ensure 100% security.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago