WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Vulnerability Awareness – Cisco IOS XE Devices Targeted in Recent Zero-Day Exploitation
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Vulnerability Awareness – Cisco IOS XE Devices Targeted in Recent Zero-Day Exploitation

Author: ian_41208

Created: Tuesday, October 17, 2023 - 17:04

Categories: Cybersecurity

Action may be required for members using impacted appliances.

Cisco Talos published details warning of recent zero-day exploitation against the Cisco IOS XE Web UI. It is believed that any switch, router, or wireless LAN controller running IOS XE with the web user interface (UI) exposed to the internet is likely vulnerable. There is currently no patch available, but Cisco is currently working on an update to address this issue. While CISA has added the vulnerability (CVE-2023-20198) to its Known Exploited Vulnerabilities Catalog, at the time of this writing, researchers are not aware of any publicly available proof-of-concept code. This compromise specifically targets Cisco IOS XE routers and switches with the Web User Interface (Web UI) feature activated, coupled with the HTTP or HTTPS Server features enabled.

System administrators are highly encouraged to confirm that vulnerable appliances are not exposed to the internet or have been hardened accordingly. Until the patch is available, Cisco advises immediate actions, including disabling web interfaces and removing management from the internet. Read more at Bleeping Computer.

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar