Cisco IOS XE exploit: SECUINFRA catches attackers

It was a spectacular operation: the security specialists at SECUINFRA caught attackers exploiting vulnerabilities in the IOS XE operating system. About two weeks ago, the SECUINFRA Falcon team published a technical advisory on the threat posed by two new vulnerabilities in Cisco appliances affecting thousands of Internet-exposed devices.

To gain an insight into the attackers’ modus operandi and how the vulnerabilities work, the security experts have set up several honeypots (intentionally vulnerable systems) to capture these details. The Falcon team at SECUINFRA has published a GitHub repository to share relevant log files and other findings with the TLP:CLEAR classification with the community. In addition, current Indicators of Compromise and further details are communicated via X (formerly Twitter) and Mastodon.

On October 28, the security experts were able to record a packet capture of an attack on two of their honeypots that contained information about the authentication bypass vulnerability CVE-2023-20198. SECUINFRA shares this information under the TLP:AMBER classification with reputable researchers in the cybersecurity community to improve detection mechanisms for this vulnerability. The SECUINFRA team would like to thank the following organizations for their cooperation in this case: Emerging Threats Labs, Corelight, Microsoft, Netresec, Nozomi Networks, Vulncheck, DIVD and LeakIX.

In addition, Horizon3.ai published a blog post about the inner workings of said vulnerability after the information we shared about X confirmed their previous hypothesis. This proof-of-concept was reported on by several cybersecurity news portals, such as BleepingComputer and Heise.

SECUINFRA is open to cooperation in future cases of this kind. If you are interested, send the security experts a message! The SECUINFRA FalconTeam publishes the latest research on the topic on X (formerly Twitter) and Mastodon.

Thomas Bode · Author

Marketing Manager

Thomas Bode ist Marketing Manager bei SECUINFRA. Neben den Marketingaufgaben ist Thomas auch für das soziale Engagement der SECUINFRA verantwortlich.

Thomas Bode ist Marketing Manager bei SECUINFRA. Seine beruflichen Wurzeln liegen in der Tourismusbranche, weshalb er bei SECUINFRA unter anderem für die Planung und Organisation von Firmenevents zuständig ist. Dabei ist es sein Ziel, nicht nur ausgefallene Reiseziele und Locations zu finden, sondern sich auch Aktivitäten auszudenken, die allen in besonderer Erinnerung bleiben und das Team weiter zusammenwachsen lassen. Neben allen marketingrelevanten Themen ist Thomas auch für das soziale Engagement der SECUINFRA verantwortlich.

Marketing Manager

Thomas Bode is Marketing Manager at SECUINFRA. In addition to marketing-related tasks, Thomas is also responsible for SECUINFRA's social commitment.

Thomas Bode is Marketing Manager at SECUINFRA. His professional roots are in the tourism industry, which is why he is responsible for planning and organizing corporate events at SECUINFRA, among other things. His goal is not only to find unusual destinations and locations, but also to come up with activities that will be remembered by everyone and that will make the team grow closer together. Besides all marketing-related topics, Thomas is also responsible for SECUINFRA's social engagement.
Beitrag teilen auf: