Security News > 2023 > October > Cisco warns of new IOS XE zero-day actively exploited in attacks

Cisco warns of new IOS XE zero-day actively exploited in attacks
2023-10-16 15:43

Cisco warned admins today of a new and maximum severity zero-day vulnerability in its IOS XE Software that can let attackers gain full administrator privileges and take complete control of affected routers.

"Cisco has identified active exploitation of a previously unknown vulnerability in the Web User Interface feature of Cisco IOS XE software when exposed to the internet or untrusted networks," the company revealed today.

Cisco identified related activity dating back to September 18 following further investigation into the attacks.

Last month, Cisco cautioned customers to patch another zero-day vulnerability in its IOS and IOS XE software targeted by attackers in the wild.

Cisco urges admins to fix IOS software zero-day exploited in attacks.

Cisco warns of VPN zero-day exploited by ransomware gangs.


News URL

https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-ios-xe-zero-day-actively-exploited-in-attacks/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 4448 231 3065 1823 609 5728