Cisco zero-day vulnerability hits 40,000+ devices in a matter of days
The Cisco zero-day vulnerability could impact thousands of customers globally


A Cisco zero-day vulnerability affecting its IOS XE Software has been found to have infected more than 41,000 devices, marking a significant increase in a matter of days.
There was previous speculation about the number of infected devices in the immediate wake of the vulnerability disclosure.
The vulnerability, tracked as CVE-2023-20198, had already been exploited with backdoors installed on 34,104 devices, according to Censys’ findings.
Originally, 50% of the 67,445 devices that use the Cisco web interface were thought to be infected. However, a further 7, 843 have been compromised by the vulnerability, bringing the total to over 41,000.
“Iterating on our current query to find potential targets, we updated it with some more generic conditionals, hoping to find even more potentially vulnerable hosts,” the Censys research team wrote in its blog.
“Unfortunately, the updates were successful, and we found even more compromised hosts this morning.”
Censys was able to tag devices that used Cisco web interfaces by deploying a new label, though that only noted whether they were running the Cisco IOS-WE web interface.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
A secondary scan using Censys data as a baseline and an open-source tool was used to analyze how widespread the vulnerability was.
RELATED RESOURCE
Discover how you can optimize your security operations
DOWNLOAD NOW
The firm’s research has highlighted particular concerns in the USA and the Philippines, which recorded the most compromised devices.
It appears that the primary targets of the vulnerability are smaller businesses and individuals, rather than larger organizations.
The zero-day vulnerability was first identified on 16 October and given a maximum CVSS rating of 10.0.
Cisco explained that it specifically affected the user interface of its IOS XE Software and that it could be used to enable an unauthorized party to gain control over an affected system. This, it said, had already been exploited in the wild.
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Cisco claims new smart switches provide next-level perimeter defense
News Cisco’s ‘security everywhere’ mantra has just taken on new meaning with the launch of a series of smart network switches.
By Solomon Klappholz
-
Cisco is jailbreaking AI models so you don’t have to worry about it
News Cisco's new AI Defense security solution helps organizations shore up LLM security by identifying potential flaws.
By Solomon Klappholz
-
Cisco dispels Kraken data breach claims, insists stolen data came from old attack
News Cisco has refuted claims it has suffered a data breach after the Kraken threat group posted stolen data online.
By Solomon Klappholz
-
Cisco patches critical flaws in Identity Services Engine
News Cisco has issued patches for a pair of critical vulnerabilities affecting its Identity Service Engine (ISE).
By Nicole Kobie
-
Your office is now absolutely riddled with surveillance equipment
News While workplace monitoring is shown to have a detrimental effect on morale, many firms are still charging ahead
By Nicole Kobie
-
Cisco confirms attackers stole data, shuts down access to compromised DevHub environment
News The tech giant insists that no sensitive customer information has been compromised
By Solomon Klappholz
-
Cisco confirms investigation amid data breach claims
News The networking giant says its probe is ongoing amid claims a threat actors accessed company data
By Nicole Kobie
-
Rubrik partners with Cisco to bolster cyber resilience
News Rubrik now integrates with Cisco XDR and is listed on the connectivity giant’s SolutionsPlus program
By Daniel Todd