A Persistent Threat: Critical Vulnerability in Network Devices

25/04/2024

A Persistent Threat: Critical Vulnerability in Network Devices
Designed by Freepik

By Guillermo Pereyra, Security Analyst at LACNIC CSIRT

A known vulnerability

In mid-October 2023, CISCO published CVE-2023-20198, a vulnerability that affects the user interface (web UI feature) of Cisco IOS XE software.

This vulnerability allows gaining unauthorized access to an exposed web interface and execute commands for creating a user.

In this article, we will discuss how this vulnerability affects the Latin American and Caribbean region, what measures LACNIC CSIRT is taking, and what we can do to fix this problem.

A vulnerability that affects our region

At LACNIC CSIRT, we’ve noticed an increase in the number of devices in the region affected by this vulnerability since its publication.

Data shows that an average of 17 compromised devices have been detected daily over the last five months, as illustrated in the graph below.

Graph #1. Number of compromised network devices over time.

An analysis of the data shows that the problem affects approximately 900 different ASNs. In the following graph, it is interesting to see how the problem is concentrated in just a few ASNs.

(Free access, no subscription required)

Graph #2. Number of compromised devices by ASN based on their assigned IP prefix.

Although updates and fixes have been available for over five months, thousands of network devices are still vulnerable to this problem.

Actions taken by LACNIC CSIRT

The LACNIC response team informs organizations with an exposed IOS XE web service that they might be vulnerable.

The views expressed by the authors of this blog are their own and do not necessarily reflect the views of LACNIC.

Subscribe
Notify of

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments