April 24, 2025
Trending News

Cisco releases patches for the second security vulnerability in iOS XE

  • October 24, 2023
  • 0

Investigations into an exploited zero day in the web UI of Cisco IOS XE software have uncovered a new vulnerability. The company has since released several patches. A

Cisco releases patches for the second security vulnerability in iOS XE

Cisco

Investigations into an exploited zero day in the web UI of Cisco IOS XE software have uncovered a new vulnerability. The company has since released several patches.

A week ago, a zero-day vulnerability was discovered at Cisco that has been actively exploited since September. During the investigation following this discovery, the Cisco team discovered a second vulnerability, also in the IOS XE software. The company has now released patches for both issues.

An accident never comes alone

The new vulnerability is called CVE-2023-20273 and has a CVSS score of 7.2, which is less critical than the first zero-day. Attackers went through another web UI component to access the file system as a new local user.

The updated planning code

Both vulnerabilities are being monitored by the Cisco team. The company has also put together an advice page for the two errors.

The released patches are included in the updates to version 17.9, which is now available. As in the previous case, Cisco recommends disabling HTTP/S servers on systems located on the Internet.

Last month, Cisco expanded its security by acquiring cybersecurity company Splunk. It was the company’s most expensive purchase to date.

Source: IT Daily

Leave a Reply

Your email address will not be published. Required fields are marked *