Update: October 20: Cisco provided an update on its investigation into the exploitation of the Web UI feature in IOS-XE. In addition to the zero-day vulnerability (CVE-2023-20198) disclosed on October 16, the Talos team has identified another previously unknown vulnerability (CVE-2023-20273) that allows an attacker to exploit a different component of the Web UI feature. The latest assigned issue has a CVSS score of 7.2 out of 10. The first fixed software releases for both vulnerabilities are expected to be posted to the Cisco Software Download Center on October 22.

Cisco issued an advisory this week concerning a critical zero-day privilege escalation vulnerability (CVE-2023-20198) in the Web User Interface (Web UI) feature of Cisco IOS XE software. Despite the seriousness of this security flaw, there are no current workarounds for the issue, but its top executives promised timely updates as the team worked on a patch and recommended disabling the HTTP server feature on internet-facing systems.

The vulnerability has been ranked as the highest criticality score of 10 in the Common Vulnerability Scoring System (CVSS). The bug would permit remote attackers, even without authentication, to gain full administrative access, thereby allowing them potential control over the affected router, paving the way for further unauthorized activity.

Upon discovery, the Cisco Talos threat intelligence team confirmed active exploitation of this vulnerability. “This affects both physical and virtual devices running Cisco IOS XE software that also have the HTTP or HTTPS Server feature enabled,” the team wrote in a blog post.

“Successful exploitation of this vulnerability allows an attacker to create an account on the affected device with privilege level 15 access, effectively granting them full control of the compromised device and allowing possible subsequent unauthorized activity,” the blog post reported.

Cisco's top security executives weigh in

Jeetu Patel, executive VP and GM of Security and Collaboration at Cisco, emphasized the company's belief in transparency and its dedication to providing a patch, when asked about this Cisco IOS-XE zero-day vulnerability during the Cisco Exclusive Cybersecurity, AI and Privacy Roundtable.

“We don't have a timeline [for the available patch] that we published yet, but we're working tirelessly to make sure that that happens,” he said. “The thing that we've always believed is that transparency is so important that we wanted to make sure that we just come out and let people know.

“Even though we don't have a path, which is unusual, usually, you would say, come out when you have a patch, but we're like, let's make sure that we come out and please provide us all right now and then we'll work on a patch expeditiously and make sure that we provided,” he added.

Patel reiterated Cisco’s recommendation to stop the HTTP or HTTPS Server access. Eric Wenger, senior director of technology policy at Cisco, echoed: “Essentially, this functionality most customers don't need to have on.”

This is about “resilience, which is that we have a significant challenge around pushing out patches when they're available and secure configuration guidance,” he said.

Wenger also touched on the potential role of artificial intelligence (AI) in patch applications. “Maybe this is a place where AI can help … or we can automate the ability to apply patches [and] to put secure configurations in place. Maybe that'll help us get to a secure place faster.”

Cisco Talos and Censys shed light on the active exploitation of IOS-XE zero-day vulnerability

Cisco Talos noted that the early evidence of potential malicious activity related to this vulnerability surfaced on September 28, 2023, which was later determined upon investigation to be as early as September 18.

On October 12, Talos Incident Response and Technical Assistance Center (TAC) found an additional cluster of related activity that began on that same day and the activity included several subsequent actions.

“We assess that these clusters of activity were likely carried out by the same actor. Both clusters appeared close together, with the October activity appearing to build off the September activity. The first cluster was possibly the actor’s initial attempt and testing their code, while the October activity seems to show the actor expanding their operation to include establishing persistent access via deployment of the implant,” the team wrote.

Additionally, data presented by Censys’s cybersecurity research team added another layer of urgency to the situation. Their findings revealed that this Cisco IOS-XE zero-day vulnerability has been exploited to plant backdoors in tens of thousands of devices.

The team observed more than half of the 67,445 hosts utilizing the Cisco web interface —34,140 devices — that appear to have the backdoor installed, indicating they have been compromised, by the time they post the blog. And the majority of these compromises occurred in the United States and the Philippines.

Additionally, Censys's research team found that the primary targets of this vulnerability aren't large corporations but rather smaller entities and individuals who are more susceptible to attacks.