<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco IOS XE software vulnerability in Webex Administration</title>
    <link>https://community.cisco.com/t5/webex-administration/cisco-ios-xe-software-vulnerability/m-p/4942916#M5037</link>
    <description>&lt;P&gt;check below effected devices :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z" target="_blank"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Oct 2023 11:32:10 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2023-10-18T11:32:10Z</dc:date>
    <item>
      <title>Cisco IOS XE software vulnerability</title>
      <link>https://community.cisco.com/t5/webex-administration/cisco-ios-xe-software-vulnerability/m-p/4942909#M5036</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Can you please check for this&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Cisco IOS XE software (CVE-2023-20198 is a privilege escalation vulnerability affecting Cisco IOS XE software),&lt;/STRONG&gt; receiving the highest possible CVSS score of 10?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Is this affecting our Cisco devices or not?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;If yes, please share the process to remediate this&amp;nbsp;vulnerability.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 11:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/cisco-ios-xe-software-vulnerability/m-p/4942909#M5036</guid>
      <dc:creator>yashasvi kesamreddy</dc:creator>
      <dc:date>2023-10-18T11:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IOS XE software vulnerability</title>
      <link>https://community.cisco.com/t5/webex-administration/cisco-ios-xe-software-vulnerability/m-p/4942916#M5037</link>
      <description>&lt;P&gt;check below effected devices :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z" target="_blank"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 11:32:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/cisco-ios-xe-software-vulnerability/m-p/4942916#M5037</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-10-18T11:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IOS XE software vulnerability</title>
      <link>https://community.cisco.com/t5/webex-administration/cisco-ios-xe-software-vulnerability/m-p/4942918#M5038</link>
      <description>&lt;P&gt;We are not sure about this.&lt;/P&gt;&lt;P&gt;Can you please elaborate more on this information.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 11:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/cisco-ios-xe-software-vulnerability/m-p/4942918#M5038</guid>
      <dc:creator>yashasvi kesamreddy</dc:creator>
      <dc:date>2023-10-18T11:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco IOS XE software vulnerability</title>
      <link>https://community.cisco.com/t5/webex-administration/cisco-ios-xe-software-vulnerability/m-p/4943302#M5040</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1616263"&gt;@yashasvi kesamreddy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;as the security advisory states all devices running IOS-XE (e.g. switches, routers, access points, etc.) are affected, if the HTTP/HTTPS web server is enabled.&lt;/P&gt;
&lt;P&gt;Here is a list of devices which use IOS-XE:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/ios-nx-os-software/ios-xe/index.html#~products" target="_blank"&gt;Cisco IOS XE - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In order to be vulnerable, the following commands (or either one of them) must be present in the configuration:&lt;/P&gt;
&lt;P&gt;ip http server&lt;/P&gt;
&lt;P&gt;ip http secure-server&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As the security advisory implies the vulnerability can be mitigated by disabling this feature (no ip http server / no ip http secure-server), if it is not required. If it is required, then you should block the web access to the vulnerable devices from untrusted networks.&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;Igor&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 22:02:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/webex-administration/cisco-ios-xe-software-vulnerability/m-p/4943302#M5040</guid>
      <dc:creator>Igor Lukic</dc:creator>
      <dc:date>2023-10-18T22:02:27Z</dc:date>
    </item>
  </channel>
</rss>

