10 out of 10: A critical zero-day vulnerability found in Cisco IOS XE allowed full control over 10,000 devices.

Cisco has reported the discovery of a previously unknown zero-day vulnerability CVE-2023-20198 in the Cisco IOS XE web server. The vulnerability affects both physical and virtual devices running Cisco IOS XE that have the HTTP(S) server feature enabled. It received the highest danger rating — 10 out of 10 on the CVSS scale. The patch to address the vulnerability is not yet ready. This vulnerability allows an attacker to create an account with maximum privilege level (15) on an internet-connected device without authentication, giving them complete control over the compromised system. The company stated that it tracked how an attacker exploited the vulnerability to gain administrator-level privileges on devices running IOS XE and then, bypassing patches, used an old remote code execution (RCE) vulnerability from 2021 (CVE-2021-1435) to install a Lua implant on the affected systems.
Source: 3dnews.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster