%SYS-5-CONFIG_P: Configured programmatically by process SEP_webui_wsma_http from console as user on line
%SEC_LOGIN-5-WEBLOGIN_SUCCESS: Login Success [user: user] [Source: source_IP_address] at 03:42:13 UTC Wed Oct 11 2023
复制代码
注意:
对于用户访问 Web UI 的每个实例,都会表现 %SYS-5-CONFIG_P 消息。要查找的指示器是消息中存在的新用户名或未知用户名。
2、查抄系统日记中是否有以下消息,此中文件名是与预期文件安装操作无关的未知文件名:
%WEBUI-6-INSTALL_OPERATION_INFO: User: username, Install Operation: ADD filename It should go without saying but the HTTP and HTTPS server feature should never be enabled on internet-facing systems as is consistent with long-established best practices. Cisco reiterated the guidance in Monday’s advisory.
复制代码
思科通告:Cisco IOS XE Software Web UI Privilege Escalation Vulnerability