Rewterz

Rewterz Threat Alert – WSHRAT aka Houdini – Active IOCs

May 18, 2023
Rewterz

Rewterz Threat Advisory – Multiple Cisco Small Business Series Switches Vulnerabilities

May 18, 2023

Rewterz Threat Advisory – CVE-2022-208640 – Cisco IOS XE ROM Monitor Vulnerabilities

Severity

High

Analysis Summary

CVE-2022-208640

Cisco IOS XE ROM Monitor could allow a physically proximate attacker to obtain sensitive information, caused by a problem with the file and boot variable permissions in ROMMON. By rebooting the switch into ROMMON and entering specific commands through the console, an attacker could exploit this vulnerability to read any file or reset the enable password.

Impact

  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2022-208640

Affected Vendors

Cisco

Affected Products

  • Cisco Catalyst 9200 Series Switches
  • Cisco Catalyst 9300 Series Switches
  • Cisco Catalyst 9500 Series Switches
  • Cisco Catalyst 9400 Series Switches

Remediation

Refer to Cisco Security Advisory for patch, upgrade or suggested workaround information. 

Cisco Security Advisory

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.