Security News > 2023 > October > Exploit released for critical Cisco IOS XE flaw, many hosts still hacked

Exploit released for critical Cisco IOS XE flaw, many hosts still hacked
2023-10-31 03:09

Public exploit code is now available for the critical Cisco IOS XE vulnerability tracked as CVE-2023-20198 that was leveraged as a zero-day to hack tens of thousands of devices.

Cisco released patches for most releases of its IOS XE software but thousands of systems continue to be compromised, internet scans show.

LeakIX, an intelligence platform for exposed online services, confirmed that the exploit that Secuinfra also observed could successfully hijack Cisco IOS XE devices.

Ten days after that, the Censys platform for threat hunting found on October 25 around 28,000 Cisco IOS XE hosts showing signs of compromise spread all over the world.

Cisco patches IOS XE zero-days used to hack over 50,000 devices.

Over 10,000 Cisco devices hacked in IOS XE zero-day attacks.


News URL

https://www.bleepingcomputer.com/news/security/exploit-released-for-critical-cisco-ios-xe-flaw-many-hosts-still-hacked/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-10-16 CVE-2023-20198 Unspecified vulnerability in Cisco IOS XE
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
network
low complexity
cisco
critical
10.0

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 4442 231 3052 1816 604 5703