<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-2268 Information about the Cisco IOS XE Software (CVE-2023-20198 &amp; CVE-2023-20273)</title><link>https://community.appian.com/support/w/kb/3411/kb-2268-information-about-the-cisco-ios-xe-software-cve-2023-20198-cve-2023-20273</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-2268 Information about the Cisco IOS XE Software (CVE-2023-20198 &amp; CVE-2023-20273)</title><link>https://community.appian.com/support/w/kb/3411/kb-2268-information-about-the-cisco-ios-xe-software-cve-2023-20198-cve-2023-20273</link><pubDate>Wed, 01 Nov 2023 21:40:09 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:38d8d1a3-4c64-4165-9704-ced08913abb0</guid><dc:creator>Kevin Kleinegger</dc:creator><comments>https://community.appian.com/support/w/kb/3411/kb-2268-information-about-the-cisco-ios-xe-software-cve-2023-20198-cve-2023-20273#comments</comments><description>Current Revision posted to Appian Knowledge Base by Kevin Kleinegger on 11/1/2023 9:40:09 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 27-Oct-2023, CISA released a &lt;/span&gt;&lt;a href="https://www.cisa.gov/news-events/alerts/2023/10/27/cisa-updates-guidance-addressing-cisco-ios-xe-web-ui-vulnerabilities-additional-releases"&gt;&lt;span style="font-weight:400;"&gt;security advisory&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; for all organizations utilizing Cisco&amp;rsquo;s Internetworking Operating System (IOS) XE Software Web User Interface (UI).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Upon assessing the Appian platform against all details of the CVEs (CVE-2023-20198 and CVE-2023-20273), we can confirm that the Appian platform is not impacted by the vulnerability described in the security advisory. We will continue to monitor the situation and provide any updates as appropriate.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20198"&gt;&lt;span style="font-weight:400;"&gt;CVE-2023-20198&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Vulnerability in the web UI feature of Cisco IOS XE Software)&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20273"&gt;&lt;span style="font-weight:400;"&gt;CVE-2023-20273&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Vulnerability in the web UI feature of Cisco IOS XE Software)&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.cisa.gov/news-events/alerts/2023/10/27/cisa-updates-guidance-addressing-cisco-ios-xe-web-ui-vulnerabilities-additional-releases"&gt;&lt;span style="font-weight:400;"&gt;https://www.cisa.gov/news-events/alerts/2023/10/27/cisa-updates-guidance-addressing-cisco-ios-xe-web-ui-vulnerabilities-additional-releases&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z"&gt;&lt;span style="font-weight:400;"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last reviewed: October 31, 2023&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Security&lt;/div&gt;
</description></item><item><title>DRAFT SP-9355 Information about the Cisco IOS XE Software (CVE-2023-20198 &amp; CVE-2023-20273)</title><link>https://community.appian.com/support/w/kb/3411/kb-2268-information-about-the-cisco-ios-xe-software-cve-2023-20198-cve-2023-20273/revision/1</link><pubDate>Wed, 01 Nov 2023 21:38:39 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:38d8d1a3-4c64-4165-9704-ced08913abb0</guid><dc:creator>Kevin Kleinegger</dc:creator><comments>https://community.appian.com/support/w/kb/3411/kb-2268-information-about-the-cisco-ios-xe-software-cve-2023-20198-cve-2023-20273#comments</comments><description>Revision 1 posted to Appian Knowledge Base by Kevin Kleinegger on 11/1/2023 9:38:39 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 27-Oct-2023, CISA released a &lt;/span&gt;&lt;a href="https://www.cisa.gov/news-events/alerts/2023/10/27/cisa-updates-guidance-addressing-cisco-ios-xe-web-ui-vulnerabilities-additional-releases"&gt;&lt;span style="font-weight:400;"&gt;security advisory&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; for all organizations utilizing Cisco&amp;rsquo;s Internetworking Operating System (IOS) XE Software Web User Interface (UI).&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Upon assessing the Appian platform against all details of the CVEs (CVE-2023-20198 and CVE-2023-20273), we can confirm that the Appian platform is not impacted by the vulnerability described in the security advisory. We will continue to monitor the situation and provide any updates as appropriate.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20198"&gt;&lt;span style="font-weight:400;"&gt;CVE-2023-20198&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Vulnerability in the web UI feature of Cisco IOS XE Software)&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20273"&gt;&lt;span style="font-weight:400;"&gt;CVE-2023-20273&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Vulnerability in the web UI feature of Cisco IOS XE Software)&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.cisa.gov/news-events/alerts/2023/10/27/cisa-updates-guidance-addressing-cisco-ios-xe-web-ui-vulnerabilities-additional-releases"&gt;&lt;span style="font-weight:400;"&gt;https://www.cisa.gov/news-events/alerts/2023/10/27/cisa-updates-guidance-addressing-cisco-ios-xe-web-ui-vulnerabilities-additional-releases&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z"&gt;&lt;span style="font-weight:400;"&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z&lt;/span&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last reviewed: October 31, 2023&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Security&lt;/div&gt;
</description></item></channel></rss>