Skip to content

Commit

Permalink
Update DIVD-2023-00038.md
Browse files Browse the repository at this point in the history
  • Loading branch information
Ralphhorn authored Oct 18, 2023
1 parent 4c9f9bf commit 57d2575
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions _cases/2023/DIVD-2023-00038.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,11 +34,11 @@ timeline:
---
## Summary

On October 16th, Cisco disclosed an authentication bypass vulnerability affecting Cisco IOS-XE appliances with CVE-ID CVE-2023-20198. An unknown threat actor is actively placing implants on the vulnerable appliances worldwide. This is a serious situation as implants allow threat actors to monitor traffic, gain access to the underlying system and pivot into protected networks. For additional guidance, please find the Cisco PSIRT advisory at the bottom of this page.
On October 16th, Cisco disclosed an authentication bypass vulnerability affecting Cisco IOS-XE appliances with CVE-ID CVE-2023-20198. An unknown threat actor is actively placing implants on the vulnerable appliances worldwide. This is a serious situation as implants allow threat actors to monitor traffic, gain access to the underlying system and move into protected networks. For additional guidance, please find the Cisco PSIRT advisory at the bottom of this page.

## Recommendations

Given that no patch is yet available, disable HTTP(S) access to any management interfaces if possible. If HTTP(S) access is required, implement an Access Control List to limit access.
No patch is currently available, therefore disable HTTP(S) access to any management interfaces if possible. If HTTP(S) access is required, implement an Access Control List to limit access.

## What we are doing

Expand Down

0 comments on commit 57d2575

Please sign in to comment.