Security researcher Dimitris Roussi explains that a recent critical vulnerability in the WEB-UI application of Cisco's IOS XE operating system makes thousands of network devices worldwide vulnerable, including devices located in Greece.

The vulnerability, which has the identifier CVE-2023-20198, has received the maximum severity rating of 10.0 on the Common Vulnerability Scoring System (CVSSv3) scale.
An attacker exploiting this vulnerability in a CISCO device, which allows access via the Internet to the WEB-U application, initially gains access to the device by creating a privileged user account.
Then, by exploiting the privileged account, it creates an additional local user account with standard privileges. Finally, through the local user account and by exploiting an additional vulnerability which has been identified as CVE-2023-20273, it achieves privileged escalation to root level and can now execute code on the device with maximum privileges.
According to the SHODAN engine, over 100,000 CISCO devices have provided access to the WEB-UI over the internet and are potentially immediately exposed to a cyberattack.

Within the scope of the analysis we will attempt to study the possibility of exploiting this specific vulnerability in network devices that are geographically located (for example) in Turkey.
Initially, using an appropriate script we download data from the Shodan engine and process it to produce a list of IPs of potentially vulnerable devices that are geographically located in Turkey.

The servers.txt includes the list of IPs that will be examined.
Then, with the help of a bash script that calls an exploit implemented in python (exploit.py), a check is made for the existence of the vulnerability in all the IPs included in the servers.txt.

A portion of the Python file code that constitutes the exploit is shown below (the full code is not provided for obvious reasons).

The output is a file named vulnerable_servers.txt which contains a list of vulnerable CISCO devices.
Sample entries of the list:

As a final verification of the existence and exploitation of the vulnerability, we can execute commands on vulnerable devices through exploit.py
As an example, we will execute the command “uname –a”*for the ip 31.145.81.113 .
* This command was chosen because it does not cause any damage to the vulnerable device; it simply displays information about the installed operating system version.

As we observe, we managed to execute the command remotely on the above device.
The seriousness and impact of this particular vulnerability are now evident
Mitigation methods for the vulnerability:
CISCO has recently issued the appropriate fixes to address the vulnerability which are recommended to be implemented immediately. A link with more information is provided.
(https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-xe-dublin-17121/221128-software-fix-availability-for-cisco-ios.html)

Additionally, regardless of applying the fixes (patch), it is recommended to restrict access to the WEB-UI over the internet and to provide access to it only within the corporate network.
*Dimitris Roussi is a member of the Information Systems Security Laboratory of the University of the Aegean.
