Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cisco disclosed active exploitation of two vulnerabilities in the web UI of Cisco IOS XE Software in October 2023. The affected scope is not every Cisco device: the risk described by Cisco applies to IOS XE devices with the Web UI HTTP Server feature enabled. Administrators should verify each device’s software and configuration, look for Cisco’s compromise indicators, reduce web UI exposure, and select a compatible fixed release using Cisco’s current guidance.

What happened in the Cisco IOS XE attacks?

Cisco described an actively exploited two-vulnerability chain. Attackers first used CVE-2023-20198 to gain initial access and issue a privilege 15 command that created a local username and password. They then used CVE-2023-20273 through another web UI component to gain root privileges and write an implant to the device file system. Cisco assigned CVSS 3.1 base scores of 10.0 to CVE-2023-20198 and 7.2 to CVE-2023-20273. These are Cisco’s published assessments and attack description. Cisco’s advisory was first published October 16, 2023, and its final version 2.6 was updated November 1, 2023.

Is my product affected?

Cisco says the vulnerabilities affect Cisco IOS XE Software when its Web UI feature is enabled. The relevant HTTP Server feature is enabled by either ip http server or ip http secure-server. Cisco’s advisory lists ASA Software, Firepower Threat Defense, ISE, traditional IOS, IOS XE before Release 16, and NX-OS as not affected by these vulnerabilities. This is not a claim that all Cisco routers and switches are vulnerable; both the software family and web UI configuration matter.

Check the software version and web UI configuration

  1. Connect to the device CLI and run show version to identify the software release and platform. Cisco TAC’s October 26, 2023 FAQ says IOS XE versions 16.x and later are in scope; examples it gives include 16.3.5, 16.12.4, 17.3.5, 17.6.1, and 17.9.4. Confirm the exact release and platform in Cisco’s current advisory or Software Checker rather than treating a version-family example as a definitive status.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Run show running-config | include ip http server|secure|active. Cisco says either ip http server or ip http secure-server indicates that the HTTP Server feature is enabled.

  3. Review any active-session-module settings in the output. Cisco states that ip http active-session-modules none makes the HTTP path not exploitable, while ip http secure-active-session-modules none makes the HTTPS path not exploitable.

For Cisco’s affected-product and identification guidance, see the Cisco TAC technical FAQ. The 2023 FAQ and advisory do not establish the current exposure or compromise status of an individual device; that depends on its actual release, configuration, and logs.

Rank #2
Cisco Meraki MX67-HW Wired Network Security/Firewall - Appliance Only
  • Stateful firewall throughput: 450 Mbps.
  • Recommended maximum clients: 50.
  • Managed centrally over the web. Classifies applications, users and devices.
  • Layer 7 application visibility and traffic shaping. Application prioritization.
  • Dimensions: 9.4 x 5.1 x 1.1 inches. Weight: 1.54 lbs (24.69 ounces).

How should you reduce exposure?

Cisco recommends disabling the HTTP Server feature on internet-facing systems where it is not needed, or restricting access to trusted source addresses. If both HTTP and HTTPS server commands are configured, disabling only one does not close exposure through the other; address both. Cisco describes disabling the server as a mitigation until upgrade, not a replacement for fixed software.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Disabling HTTP/HTTPS can disrupt deployment-specific functions. Cisco TAC lists possible effects including C9800 WLC web management, day-zero setup, web-authentication and guest workflows, RESTCONF, and ISE redirect workflows that depend on HTTP services. The FAQ advises using an ACL restricted to trusted subnets or addresses when those services must remain available. Cisco says disabling the server generally does not affect Cisco DNA Center device management or Smart Licensing, with an exception where CSLU external application or SSM On-Prem uses RESTCONF to retrieve RUM reports. Validate the impact against the actual device and services before changing production configuration.

Cisco also says an attacker can create a local user regardless of the authentication method, including where AAA is in place. The credentials are local to the exploited device, not the AAA system. AAA therefore should not be treated as a substitute for exposure reduction or patching.

Rank #3
Cisco Meraki MX68-HW Wired Network Security/Firewall - Appliance Only
  • 10 × GbE (2 WAN, 2 PoE+), 1 × USB 2.0 for 3G/4G failover
  • Stateful firewall throughput: 450 Mbps, VPN throughput: 200 Mbps
  • Recommended maximum clients: 50, Layer 7 application visibility and traffic shaping
  • Automatic firmware upgrades and security patches, VLAN support and DHCP services
  • Includes 100W DC Power Supply, requires Enterprise or Advanced Security License

How do you check for signs of compromise?

Use Cisco’s advisory as the authoritative incident-response reference and review the device for multiple indicators rather than treating a single generic message as proof.

  • Check for unexpected local usernames. Cisco’s examples include cisco_tac_admin and cisco_support; investigate any account that is not recognized and authorized in your environment.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Review configuration activity and logs for the process string SEP_webui_wsma_http, as well as unknown install operations. Cisco provides this example pattern: %SYS-5-CONFIG_P: Configured programmatically by process SEP_webui_wsma_http from console as user on line. Cisco cautions that this message can also occur during legitimate web UI use, so the process string alone is not conclusive.

    Rank #4
    Sale
    Cisco Meraki MX68CW-HW Network Security Firewall Appliance w/ Power Adapter & Antennas [Unclaimed & No License] (Renewed)
    • MX68CW include a SIM slot and internal LTE modem. This integrated functionality removes the need for external hardware and allows for cellular visibility and configuration within the Meraki dashboard.
    • One CAT 6, 300 Mbps LTE modem + 1 x Nano SIM slot (4ff form factor) +++ Global coverage with individual orderable SKUs for North America and worldwide
    • MX68CW include two ports with 802.3at (PoE+). This built-in power capability removes the need for additional hardware to power critical branch devices.
    • WAN: 2 GbE, one Cat 6 modem, one USB (cellular failover) + LAN: 10 GbE (two PoE+); Wi-Fi: 802.11ac Wave 2 + 600 Mbps firewall throughput
    • Supports up to 50 users + 300 Mbps site-to-site VPN throughput
  • Cisco Talos documented a command in the advisory to query the device’s logout-confirm endpoint; Cisco says a hexadecimal string response indicates the implant is present. Use the command and authorization value exactly as Cisco publishes them in the advisory, and only on systems you administer.

  • Review Cisco’s Snort rule IDs in the advisory for attempted exploitation, implant injection, and implant interaction, and follow its current incident-response instructions.

If indicators warrant concern, preserve relevant logs and follow your organization’s incident-response process and Cisco’s current guidance. The checks above are Cisco-documented indicators; they do not determine an individual device’s status without investigation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Cisco 3000 Network Security/Firewall Appliance
  • 2 X 10/100/1000 + 2 X GIGABIT SFP
  • CHASIS 64 GB MSATA
  • DC POWER
  • DIN RAIL MOUNTABLE
  • INDUSTRIAL SECURITY APPLIANCE
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which Cisco IOS XE releases fixed the vulnerabilities?

Cisco’s final advisory, updated November 1, 2023, listed the following fixed releases and software maintenance updates. These are the values from that 2023 advisory; they are not a substitute for checking Cisco’s current release and platform matrix.

Release train in Cisco’s 2023 advisory Fixed release listed Qualification
IOS XE 17.9 17.9.4a As listed in the November 1, 2023 advisory
IOS XE 17.6 17.6.6a As listed in the November 1, 2023 advisory
IOS XE 17.3 17.3.8a As listed in the November 1, 2023 advisory
IOS XE 16.12 16.12.10a Catalyst 3650 and 3850 only
IOS XE 17.9, base 17.9.4 SMU listed See advisory for applicability
IOS XE 17.6, base 17.6.5 SMU listed See advisory for applicability

Before upgrading, check Cisco’s current advisory and Software Checker for the exact device model and release, then confirm memory requirements and hardware/software compatibility. Cisco notes that software access and support are subject to licensing and entitlement. Fixed software is the durable remediation; an HTTP/HTTPS mitigation reduces exposure while you plan and validate the appropriate upgrade.

Quick Recap

Bestseller No. 2
Cisco Meraki MX67-HW Wired Network Security/Firewall - Appliance Only
Cisco Meraki MX67-HW Wired Network Security/Firewall - Appliance Only
Stateful firewall throughput: 450 Mbps.; Recommended maximum clients: 50.; Managed centrally over the web. Classifies applications, users and devices.
$340.00
Bestseller No. 3
Cisco Meraki MX68-HW Wired Network Security/Firewall - Appliance Only
Cisco Meraki MX68-HW Wired Network Security/Firewall - Appliance Only
10 × GbE (2 WAN, 2 PoE+), 1 × USB 2.0 for 3G/4G failover; Stateful firewall throughput: 450 Mbps, VPN throughput: 200 Mbps
$620.00
SaleBestseller No. 4
Bestseller No. 5
Cisco 3000 Network Security/Firewall Appliance
Cisco 3000 Network Security/Firewall Appliance
2 X 10/100/1000 + 2 X GIGABIT SFP; CHASIS 64 GB MSATA; DC POWER; DIN RAIL MOUNTABLE; INDUSTRIAL SECURITY APPLIANCE
$3,600.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.