HomeSecurityVulnerability in CISCO IOS XE leaves thousands of devices vulnerable

Vulnerability in CISCO IOS XE leaves thousands of devices vulnerable

Security researcher Dimitris Roussi explains that a recent critical vulnerability in the WEB-UI application of Cisco's IOS XE operating system makes thousands of network devices worldwide vulnerable, including devices located in Greece.

CISCO IOS XE

The vulnerability, which has the identifier CVE-2023-20198, has received the maximum severity rating of 10.0 on the Common Vulnerability Scoring System (CVSSv3) scale.

An attacker exploiting this vulnerability in a CISCO device, which allows access via the Internet to the WEB-U application, initially gains access to the device by creating a privileged user account.

Then, by exploiting the privileged account, it creates an additional local user account with standard privileges. Finally, through the local user account and by exploiting an additional vulnerability which has been identified as CVE-2023-20273, it achieves privileged escalation to root level and can now execute code on the device with maximum privileges.

According to the SHODAN engine, over 100,000 CISCO devices have provided access to the WEB-UI over the internet and are potentially immediately exposed to a cyberattack.

CISCO IOS XE

Within the scope of the analysis we will attempt to study the possibility of exploiting this specific vulnerability in network devices that are geographically located (for example) in Turkey.

Initially, using an appropriate script we download data from the Shodan engine and process it to produce a list of IPs of potentially vulnerable devices that are geographically located in Turkey.

Vulnerability in CISCO IOS XE leaves thousands of devices vulnerable

The servers.txt includes the list of IPs that will be examined.

Then, with the help of a bash script that calls an exploit implemented in python (exploit.py), a check is made for the existence of the vulnerability in all the IPs included in the servers.txt.

Vulnerability in CISCO IOS XE leaves thousands of devices vulnerable

A portion of the Python file code that constitutes the exploit is shown below (the full code is not provided for obvious reasons).

Vulnerability in CISCO IOS XE leaves thousands of devices vulnerable

The output is a file named vulnerable_servers.txt which contains a list of vulnerable CISCO devices.

Sample entries of the list:

CISCO IOS XE

As a final verification of the existence and exploitation of the vulnerability, we can execute commands on vulnerable devices through exploit.py

As an example, we will execute the command “uname –a”*for the ip 31.145.81.113 .

* This command was chosen because it does not cause any damage to the vulnerable device; it simply displays information about the installed operating system version.

Vulnerability in CISCO IOS XE leaves thousands of devices vulnerable

As we observe, we managed to execute the command remotely on the above device.

The seriousness and impact of this particular vulnerability are now evident

Mitigation methods for the vulnerability:

CISCO has recently issued the appropriate fixes to address the vulnerability which are recommended to be implemented immediately. A link with more information is provided.

(https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-xe-dublin-17121/221128-software-fix-availability-for-cisco-ios.html)

Vulnerability in CISCO IOS XE leaves thousands of devices vulnerable

Additionally, regardless of applying the fixes (patch), it is recommended to restrict access to the WEB-UI over the internet and to provide access to it only within the corporate network.

*Dimitris Roussi is a member of the Information Systems Security Laboratory of the University of the Aegean.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS