There's not a lot worse that can happen to your network than to have the Bad Guys take it over. That's what's happened to gobs of iOS boxes:
The main bug being used in the exploit chain exists in the Web UI of IOS XE (CVE-2023-20198). It ranks 10 out of 10 on the CVSS vulnerability-severity scale, and gives unauthenticated, remote attackers a way to gain initial access to affected devices and create persistent local user accounts on them.
The exploit method also involves a second zero-day (CVE-2023-20273), which Cisco only discovered while investigating the first one, which allows the attacker to elevate privileges to root and write an implant on the file system. Cisco released updated versions of IOS XE addressing the flaws on Oct. 22, days after disclosure, giving cyberattackers ample opportunity to go after legions of unpatched systems.
So first of all, patch your damn routers. Second, replace any network admin who can't grok iOS command line and disable the stupid web GUI. I mean, this isn't rocket surgery - anyone who can figure out subnet masking can configure things via CLI.




