Cisco has warned administrators about a new, maximum severity zero-day vulnerability in IOS XE software that could allow unauthorized attackers to gain full administrator privileges and take complete control of affected routers and switches remotely.
See also: Cisco fixes vulnerability in Cisco Emergency Responder

The company says the critical vulnerability (recorded as CVE-2023-20198) only affects devices running with the Web UI feature enabled, which also has the HTTP or HTTPS.
" Cisco has discovered the active exploitation of a previously unknown vulnerability in the Web User Interface (Web UI) feature of Cisco IOS XE Software (CVE-2023-20198) when exposed to the internet or untrusted networks ," the company revealed
“Successful exploitation of this vulnerability allows an attacker to create an account on the affected device with privilege level 15 access, allowing them to take full control of the compromised device and enable potential unauthorized activities.“
The attacks were detected on September 28 by Cisco's Technical Assistance Center (TAC), following reports of unusual behavior on a customer device.
Upon further investigation into the attacks, Cisco identified related activity dating back to September 18. The malicious activity involved the creation of a local user account by an authorized user named “cisco_tac_admin” from a suspicious IP address (5.149.249[.]74).
On October 12, the company discovered additional activity related to the CVE-2023-20198 exploit, when a local user account “cisco_support” was created from a second suspicious IP address (154.53.56[.]231). The attackers also installed a malicious plugin to execute arbitrary commands at the system or IOS level.
See also: Cisco: Urges administrators to fix an IOS zero-day

The company recommends that administrators disable the HTTP server feature on systems that are accessible from the internet, in order to remove the potential attack surface and block incoming attacks. If both HTTP and HTTPS servers are used, both commands are required to disable the HTTP server function.
Businesses are strongly advised to consider the existence of unexplained or recently created user accounts as possible indications of malicious activity associated with this threat.
One approach to detecting malicious integration on compromised Cisco IOS XE devices involves running the following command on the device, where the replacement “DEVICEIP” represents the IP address being examined:
curl -k -X POST "https[:]//DEVICEIP/webui/logoutconfirm.html?logon_hash=1"
Last month, Cisco warned its customers to update another zero-day vulnerability (CVE-2023-20109) in its IOS and IOS XE software that was targeted by external actors.
See also: Cisco acquires cybersecurity company Splunk
Cisco, as one of the global leaders in IT and telecommunications, plays a critical role in detecting and protecting against zero-day attacks.
Zero-day attack detection
With the help of advanced technology and a team of security analysts, Cisco is able to detect any new, unknown zero-day attacks that may affect its customers' systems. Cisco also uses machine learning and artificial intelligence technology to detect and block zero-day attacks. Machine learning algorithms analyze data and network behavior to detect anomalies and attacks that have not been previously identified. This automated detection method allows Cisco to quickly and effectively address zero-day attacks.
Protection from Zero-day attacks
As part of its commitment to security, Cisco also offers high-level zero-day protection. This includes creating complex solutions to address and eliminate threats before they reach the end user.
Update on the current IOS XE threat
The company is working tirelessly to address the threat and provide security solutions to its customers.
Source: bleepingcomputer
