cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
587
Views
0
Helpful
10
Replies

C9800 spam in the log

Clem58
Level 3
Level 3

Hello,

We have a cluster of 2xC9800-CL and one C9800-40 WLCs, and both face some spam into the logs :

%SYS-5-CONFIG_P: Configured programmatically by process SEP_webui_wsma_http from console as xx on vty0
%SYS-5-CONFIG_P: Configured programmatically by process SEP_webui_wsma_http from console as xx on vty0
%SYS-5-CONFIG_P: Configured programmatically by process SEP_webui_wsma_http from console as xx on vty0

I did not find anything relevant in the Cisco bugs articles, do you know how we can have this informational spams to be stopped ?

10 Replies 10

marce1000
VIP
VIP

 

  - This could be due to a (the)  security bug in IOS-XE ; you need to upgrade to at minimum 17.9.4a to mitigate it , will post more details soon, 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

marce1000
VIP
VIP

 

  - Added reply : 
              https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/ios-xe-dublin-17121/221128-software-fix-availability-for-cisco-ios.html
                  https://tools.cisco.com/bugsearch/bug/CSCwh87343

             An 'external article' : https://thesecmaster.com/protect-your-cisco-devices-from-cve-2023-20198-a-critical-privilege-escalation-vulnerability-in-cisco-ios-xe/

 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

They are on the latest 17.13.1 version

 

                      >...They are on the latest 17.13.1 version
 - Following the bug report that release is fixed : check administrative users configured in the controller anyway (running config and check if they are all authorized and known admins) . Meaning to check if the controller is not compromised.
                          If you 'like' checkout : https://github.com/smokeintheshell/CVE-2023-20198     (e.g.!)

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

We are using TACACS and I'm using a user will all privileges

 

  Ok; but that isn't exactly what I asked to verify : whether no local malicious users have been created ,

 M;



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

You'll see that every time anybody logs in to the GUI. 
If those logins correspond with your TACACS logs of authorised users then they are completely normal.
If you don't want to see them in the log then define a logging buffer filter to exclude them.
logging discriminator ...
logging buffered discriminator ...

Thanks Rich, we don't have these spams in our other IOS-XE switches, isn't there a command to specifically disable them ?

 

  - You may want to configure a logging discriminator as explained in https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/esm/configuration/xe-16-5/esm-xe-16-5-book/reliable-del-filter.html

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

You may want to configure a logging discriminator 
Already suggested that in previous reply <smile>

we don't have these spams in our other IOS-XE switches, isn't there a command to specifically disable them ?
Compare the configs?  Maybe you have a different logging level set or are already using a logging discriminator.
We've always seen those logs on all our 9800.

Review Cisco Networking for a $25 gift card