Oct. 21, 2023, 3:46 a.m. | info@thehackernews.com (The Hacker News)

The Hacker News thehackernews.com

Cisco has warned of a new zero-day flaw in IOS XE that has been actively exploited by an unknown threat actor to deploy a malicious Lua-based implant on susceptible devices.
Tracked as CVE-2023-20273 (CVSS score: 7.2), the issue relates to a privilege escalation flaw in the web UI feature and is said to have been used alongside CVE-2023-20198 as part of an exploit chain.
"The attacker first

actively exploited actor backdoor cisco cve cvss deploy devices escalation exploited flaw implant ios ios xe issue lua malicious privilege privilege escalation privilege escalation flaw score the web threat threat actor web zero-day zero-day flaw

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC