A vulnerability in Cisco IOS XE is being exploited to install a backdoor

A critical vulnerability (CVE-2023-20198) has been identified in the web interface used on Cisco physical and virtual devices that are equipped with the Cisco IOS XE operating system. This vulnerability allows for unauthorized access to the system with the highest level of privileges, provided that there is access to the network port through which the web interface operates. The danger of this issue is exacerbated by the fact that attackers have been exploiting the unpatched vulnerability for over a month to create additional accounts such as 'cisco_tac_admin' and 'cisco_support' with administrative rights, as well as to automate the deployment of a backdoor that enables remote access for command execution on the device.

Although it is recommended to limit web interface access to select hosts or the local network for proper security, many administrators leave access open from the global network. Specifically, according to Shodan, there are currently over 140,000 potentially vulnerable devices exposed to the global network. The CERT organization has already recorded around 35,000 successfully attacked Cisco devices that have been compromised with a malicious implant.

Until a patch is released to fix the vulnerability, it is advised as a workaround to disable the HTTP and HTTPS servers on the device by using the console commands 'no ip http server' and 'no ip https secure-server', or to restrict access to the web interface on the firewall. To check for the presence of a malicious implant, a request should be made: curl -X POST http://IP-of-device/webui/logoutconfirm.html?logon_hash=1, which will return an 18-character hash in case of compromise. The device logs can also be analyzed for unauthorized connections and operations related to the installation of additional files. %SYS-5-CONFIG_P: Configured programmatically by process SEP_webui_wsma_http from console as user on line %SEC_LOGIN-5-WEBLOGIN_SUCCESS: Login Success [user: user] [Source: source_IP_address] at 05:41:11 UTC Wed Oct 17 2023 %WEBUI-6-INSTALL_OPERATION_INFO: User: username, Install Operation: ADD filename

If compromised, removing the implant is as simple as rebooting the device. Accounts created by the attacker remain after the reboot and must be deleted manually. The implant is located in the file /usr/binos/conf/nginx-conf/cisco_service.conf and includes 29 lines of Lua code that enable the execution of arbitrary commands at the system level or Cisco IOS XE command interface in response to an HTTP request with a specific set of parameters.

A vulnerability in Cisco IOS XE is being exploited to install a backdoor


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster