Oct. 30, 2023, 4:26 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Overview


This month, Cisco released a security advisory regarding two vulnerabilities currently being actively exploited in actual attacks: CVE-2023-20198 and CVE-2023-20273.


These vulnerabilities are present in the web UI feature of Cisco IOS XE Software.


The CVE-2023-20198 vulnerability allows an unauthorized threat actor to create an arbitrary account with level 15 privileges, which is the highest level of access permission possible, and take control over the system. The CVE-2023-20273 vulnerability allows command injection which enables malicious content to be written …

account actively exploited actor advisory attacks cisco cisco ios cisco ios xe cisco ios xe software cve cve-2023-20198 cve-2023-20273 exploited feature ios ios xe malware analysis security security advisory software the web threat threat actor vulnerabilities vulnerability warning web

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC