HomeSecurityCisco: More than 40,000 IOS XE devices infected with backdoor

Cisco: More than 40,000 IOS XE devices infected with backdoor

More than 40,000 Cisco devices running the operating system have been compromised after a newly disclosed maximum severity vulnerability, known as CVE-2023-20198.

See also: Cisco: Warns of a new vulnerability in the IOS XE operating system
Cisco

There is no fix or workaround available, and the only recommendation for customers to secure their devices is to “disable HTTP Server functionality on all systems that are online.”

The network of equipment running Cisco IOS XE includes enterprise switches, industrial routers, access points, wireless controllers, and branch routers. Initial estimates of the number of compromised Cisco IOS XE devices were around 10,000, and the number began to rise as security researchers scoured the internet for a more accurate estimate.

On Tuesday, LeakIX , which is used to index web services and applications exposed on the public internet, reported discovering about 30,000 infected devices, not counting rebooted recommendations.

The investigation relied on evidence of compromise (IoCs) provided by Cisco to identify a successful exploitation of CVE-2023-20198 on an exposed device and uncovered thousands of infected nodes in the United States, the Philippines and Chile. Using the same verification method from Cisco, Orange’s private CERT announced on Wednesday that there were more than 34,500 Cisco IOS XE IP addresses with a malicious backdoor as a result of the CVE-2023-20198 exploit. Orange CERT also published a Python to scan for the presence of a malicious backdoor on a network device running Cisco IOS XE.

In an update on October 18, Censys , a search platform for assessing the attack surface for internet-connected devices, reported that the number of compromised devices it detected had increased to 41,983 .

It's difficult to find the exact number of Cisco IOS XE devices accessible over the public internet, but Shodan shows around 145,000 hosts, with the majority of them located in the United States.

Security researcher Yutaka Sejiyama also searched Shodan for Cisco IOS XE devices vulnerable to CVE-2023-20198 and identified close to 90,000 hosts exposed on the web.

See also: Cisco fixes vulnerability in Cisco Emergency Responder

In the U.S., many of the devices come from communications providers such as Comcast, Verizon, Cox Communications, Frontier, AT&T, Spirit, CenturyLink, Charter, Cobridge, Windstream, and Google Fiber. Sejiyama's list also includes medical centers, universities, sheriff's offices, school districts, stores, banks, hospitals , and government agencies with Cisco IOS XE devices available online.

iOS XE

The researcher expressed concern about these practices, stating that “organizations using the equipment in this manner are likely not aware of this vulnerability or breach.”

Cisco disclosed CVE-2023-20198 on Monday, but attackers had been exploiting it since before September 28, as a zero-day, to create a high-level account on affected computers and gain full control of the device.

Cisco today updated its announcement with new IP addresses and attacker usernames, as well as new rules for Snort, an open-source network intrusion detection and prevention system.

Researchers note that the perpetrators behind these attacks use a malicious backdoor, which is not persistent and is removed after the device is rebooted. However, the new accounts he helped create are still active and “have level 15 privileges, meaning they have full administrative access to the device.”

According to Cisco's analysis, the attacker is collecting device details and performing preliminary activity. The attacker is also deleting logs and removing users, likely to hide their activity. Researchers believe that a single attacker is behind these attacks, but they have not been able to determine the initial delivery mechanism. Cisco has not disclosed further details about the attacks, but has promised to provide more information once the investigation is complete and a fix is ​​available.

See also: Cisco: Urges administrators to fix an IOS zero-day
What security measures should be taken to protect devices from this backdoor? 
In our effort to achieve the goal of maximum security, it is necessary to assess and identify potential threats. 

First, it is important to stay up-to- date on the latest vulnerabilities in software and hardware. This can be done by regularly reading relevant articles and reports and having ongoing security training. 

Recommended actions 
  1. Implementing effective security policies: Creating and implementing properly structured security policies is critical.
  2. Installing protection systems: This includes both installing powerful intrusion detection software and creating physical protection measures.
  3. Staff training: Staff must be up to date on the latest security standards and how to identify and deal with potential threats.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS