Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteCisco disclosed active exploitation of two vulnerabilities in the web UI of Cisco IOS XE Software in October 2023. The affected scope is not every Cisco device: the risk described by Cisco applies to IOS XE devices with the Web UI HTTP Server feature enabled. Administrators should verify each device’s software and configuration, look for Cisco’s compromise indicators, reduce web UI exposure, and select a compatible fixed release using Cisco’s current guidance.
What happened in the Cisco IOS XE attacks?
Cisco described an actively exploited two-vulnerability chain. Attackers first used CVE-2023-20198 to gain initial access and issue a privilege 15 command that created a local username and password. They then used CVE-2023-20273 through another web UI component to gain root privileges and write an implant to the device file system. Cisco assigned CVSS 3.1 base scores of 10.0 to CVE-2023-20198 and 7.2 to CVE-2023-20273. These are Cisco’s published assessments and attack description. Cisco’s advisory was first published October 16, 2023, and its final version 2.6 was updated November 1, 2023.
Is my product affected?
Cisco says the vulnerabilities affect Cisco IOS XE Software when its Web UI feature is enabled. The relevant HTTP Server feature is enabled by either ip http server or ip http secure-server. Cisco’s advisory lists ASA Software, Firepower Threat Defense, ISE, traditional IOS, IOS XE before Release 16, and NX-OS as not affected by these vulnerabilities. This is not a claim that all Cisco routers and switches are vulnerable; both the software family and web UI configuration matter.
Check the software version and web UI configuration
-
Connect to the device CLI and run
show versionto identify the software release and platform. Cisco TAC’s October 26, 2023 FAQ says IOS XE versions 16.x and later are in scope; examples it gives include 16.3.5, 16.12.4, 17.3.5, 17.6.1, and 17.9.4. Confirm the exact release and platform in Cisco’s current advisory or Software Checker rather than treating a version-family example as a definitive status.Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Run
show running-config | include ip http server|secure|active. Cisco says eitherip http serverorip http secure-serverindicates that the HTTP Server feature is enabled. -
Review any active-session-module settings in the output. Cisco states that
ip http active-session-modules nonemakes the HTTP path not exploitable, whileip http secure-active-session-modules nonemakes the HTTPS path not exploitable.
For Cisco’s affected-product and identification guidance, see the Cisco TAC technical FAQ. The 2023 FAQ and advisory do not establish the current exposure or compromise status of an individual device; that depends on its actual release, configuration, and logs.
Rank #2
- Stateful firewall throughput: 450 Mbps.
- Recommended maximum clients: 50.
- Managed centrally over the web. Classifies applications, users and devices.
- Layer 7 application visibility and traffic shaping. Application prioritization.
- Dimensions: 9.4 x 5.1 x 1.1 inches. Weight: 1.54 lbs (24.69 ounces).
How should you reduce exposure?
Cisco recommends disabling the HTTP Server feature on internet-facing systems where it is not needed, or restricting access to trusted source addresses. If both HTTP and HTTPS server commands are configured, disabling only one does not close exposure through the other; address both. Cisco describes disabling the server as a mitigation until upgrade, not a replacement for fixed software.
Disabling HTTP/HTTPS can disrupt deployment-specific functions. Cisco TAC lists possible effects including C9800 WLC web management, day-zero setup, web-authentication and guest workflows, RESTCONF, and ISE redirect workflows that depend on HTTP services. The FAQ advises using an ACL restricted to trusted subnets or addresses when those services must remain available. Cisco says disabling the server generally does not affect Cisco DNA Center device management or Smart Licensing, with an exception where CSLU external application or SSM On-Prem uses RESTCONF to retrieve RUM reports. Validate the impact against the actual device and services before changing production configuration.
Cisco also says an attacker can create a local user regardless of the authentication method, including where AAA is in place. The credentials are local to the exploited device, not the AAA system. AAA therefore should not be treated as a substitute for exposure reduction or patching.
Rank #3
- 10 × GbE (2 WAN, 2 PoE+), 1 × USB 2.0 for 3G/4G failover
- Stateful firewall throughput: 450 Mbps, VPN throughput: 200 Mbps
- Recommended maximum clients: 50, Layer 7 application visibility and traffic shaping
- Automatic firmware upgrades and security patches, VLAN support and DHCP services
- Includes 100W DC Power Supply, requires Enterprise or Advanced Security License
How do you check for signs of compromise?
Use Cisco’s advisory as the authoritative incident-response reference and review the device for multiple indicators rather than treating a single generic message as proof.
-
Check for unexpected local usernames. Cisco’s examples include
cisco_tac_adminandcisco_support; investigate any account that is not recognized and authorized in your environment.Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Review configuration activity and logs for the process string
SEP_webui_wsma_http, as well as unknown install operations. Cisco provides this example pattern:%SYS-5-CONFIG_P: Configured programmatically by process SEP_webui_wsma_http from console as user on line. Cisco cautions that this message can also occur during legitimate web UI use, so the process string alone is not conclusive.Rank #4
SaleCisco Meraki MX68CW-HW Network Security Firewall Appliance w/ Power Adapter & Antennas [Unclaimed & No License] (Renewed)- MX68CW include a SIM slot and internal LTE modem. This integrated functionality removes the need for external hardware and allows for cellular visibility and configuration within the Meraki dashboard.
- One CAT 6, 300 Mbps LTE modem + 1 x Nano SIM slot (4ff form factor) +++ Global coverage with individual orderable SKUs for North America and worldwide
- MX68CW include two ports with 802.3at (PoE+). This built-in power capability removes the need for additional hardware to power critical branch devices.
- WAN: 2 GbE, one Cat 6 modem, one USB (cellular failover) + LAN: 10 GbE (two PoE+); Wi-Fi: 802.11ac Wave 2 + 600 Mbps firewall throughput
- Supports up to 50 users + 300 Mbps site-to-site VPN throughput
-
Cisco Talos documented a command in the advisory to query the device’s logout-confirm endpoint; Cisco says a hexadecimal string response indicates the implant is present. Use the command and authorization value exactly as Cisco publishes them in the advisory, and only on systems you administer.
-
Review Cisco’s Snort rule IDs in the advisory for attempted exploitation, implant injection, and implant interaction, and follow its current incident-response instructions.
If indicators warrant concern, preserve relevant logs and follow your organization’s incident-response process and Cisco’s current guidance. The checks above are Cisco-documented indicators; they do not determine an individual device’s status without investigation.
Recommended Free Tools
Best Value
- 2 X 10/100/1000 + 2 X GIGABIT SFP
- CHASIS 64 GB MSATA
- DC POWER
- DIN RAIL MOUNTABLE
- INDUSTRIAL SECURITY APPLIANCE
Which Cisco IOS XE releases fixed the vulnerabilities?
Cisco’s final advisory, updated November 1, 2023, listed the following fixed releases and software maintenance updates. These are the values from that 2023 advisory; they are not a substitute for checking Cisco’s current release and platform matrix.
| Release train in Cisco’s 2023 advisory | Fixed release listed | Qualification |
|---|---|---|
| IOS XE 17.9 | 17.9.4a | As listed in the November 1, 2023 advisory |
| IOS XE 17.6 | 17.6.6a | As listed in the November 1, 2023 advisory |
| IOS XE 17.3 | 17.3.8a | As listed in the November 1, 2023 advisory |
| IOS XE 16.12 | 16.12.10a | Catalyst 3650 and 3850 only |
| IOS XE 17.9, base 17.9.4 | SMU listed | See advisory for applicability |
| IOS XE 17.6, base 17.6.5 | SMU listed | See advisory for applicability |
Before upgrading, check Cisco’s current advisory and Software Checker for the exact device model and release, then confirm memory requirements and hardware/software compatibility. Cisco notes that software access and support are subject to licensing and entitlement. Fixed software is the durable remediation; an HTTP/HTTPS mitigation reduces exposure while you plan and validate the appropriate upgrade.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

