BadCandy Webshell Exploiting Unpatched Cisco Devices (CVE-2023-20198)
CriticalWhat happened
Cyber actors are exploiting a critical vulnerability (CVE-2023-20198) in Cisco IOS XE devices to deploy a Lua-based web shell known as BadCandy, enabling unauthorized remote command execution.
Who is affected
Organizations operating unpatched Cisco IOS XE devices with the web user interface exposed to the internet are at risk.
Why it matters
The exploitation allows attackers to gain full control over affected devices, potentially leading to data breaches, network disruptions, and further propagation of malicious activities within the network.
How it could have been prevented
Applying the security patch for CVE-2023-20198 promptly and disabling the web user interface if not necessary would have mitigated the risk.
Relevant professional terms
- Web Shell
- A malicious script that enables remote administration of a device, often used by attackers to maintain persistent access.
- Lua
- A lightweight, high-level programming language commonly used for scripting in embedded systems.
Recommended reading: Cyber.gov.au
