DETECTION OVERVIEW
Risk Factors
Internet-facing devices with the Cisco IOS XE web UI service enabled have been exploited. An unauthenticated attacker can gain control of a device, access sensitive traffic, and launch attacks on additional networks.
Category

The web interface of Cisco Internetworking Operating System (IOS) XE has a privilege escalation vulnerability that allows attackers to create an account with administrator (level 15) privileges. To exploit this vulnerability, the attacker sends a malicious HTTP request with a SOAP payload and a double URL-encoded URI that specifies the /webui_wsma_http or /webui_wsma_https endpoints. These endpoints are normally restricted, but the vulnerability enables the restriction to be bypassed (1). The victim processes the payload and sends an HTTP response with a SOAP payload that contains the account information and a 200 status code to the attacker (2). After the account is created, the attacker can chain this exploit with an exploit of CVE-2023-20273 to install malware on the device.
Network analysis and visibility solutions remain underrepresented in enterprises. Find out why in this preview of a new Wave report.
ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response
Visit this resource for more information.
This analysis exposes the critical link between an organization's lack of internal visibility and the escalating cost of compromise, demanding an urgent re-evaluation of how core business assets are protected.
Learn why you need to be wary of the claims certain network detection and response providers make about their coverage against the MITRE ATT&CK framework.
Learn how NDR from RevealX helps security teams detect and investigate more adversary TTPs in the MITRE ATT&CK framework than rule-based tools.
