home.social

#cve_2023_20198 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve_2023_20198, aggregated by home.social.

  1. Regarding the #Cisco #IOS XE web UI RCE vuln, I wanted to test a few things in a lab environment to help with forensics, detection, etc. But the software is #proprietary and it seems Cisco tries quite hard to make it inaccessible to anyone not paying them. So it's a challenge for #defenders to get some basic answers from a device they control and know is not compromised.

    #vulnerability #CVE_2023_20198 #CVE202320198

  2. New Cisco IOS XE zero day vulnerability has been disclosed as CVE-2023-20198.

    This vulnerability is being actively exploited with thousands of Cisco IOS XE devices being breached.

    This vulnerability has a CVSS score of 10/10 and affects any Cisco IOS XE devices with HTTP/HTTPS service enabled & is Internet facing. Successful exploitation by the attacker could allow them to create admin-level accounts & take over the network.

    https://arstechnica.com/security/2023/10/actively-exploited-cisco-0-day-with-maximum-10-severity-gives-full-network-control/

    #infosec #cybersecurity #Cisco #IOSXE #CVE_2023_20198 #zeroday