ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Salt Typhoon remains active, hits more telecom networks via Cisco routers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20198
Unauthenticated Privilege Escalation in Cisco IOS XE Web UI (Actively Exploited)

CVE-2023-20198 is a critical (CVSS 10.0) unauthenticated privilege escalation flaw in the web UI of Cisco IOS XE software, triggered by sending crafted network requests to the exposed web management interface. An attacker with no credentials can use the flaw to gain initial access and issue a privilege 15 command, creating a local user with normal login access; the attacker then chained CVE-2023-20273 (CVSS 7.2) to elevate that account to root and write an implant to the file system. Successful exploitation yields full administrative control of the device, including persistence via the planted implant, on Cisco IOS XE devices with the web UI enabled and reachable from the internet or untrusted networks, including Rockwell Automation Allen-Bradley Stratix 5200 and 5800 switches running IOS XE. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-16 with a BOD 23-02 directive, EPSS stands at 99.6% (100th percentile), and ongoing campaigns (including the 'BADCANDY' activity flagged by Australia's ASD and Cisco-related telecom intrusions attributed to Salt Typhoon) have been reported.

Do: Upgrade affected devices to the fixed releases listed in Cisco's advisory (use Cisco's Software Checker) and, as immediate mitigation, disable the web UI or restrict it to trusted networks/addresses only. Check for compromise by looking for unexpected local user accounts and the implant artifacts Cisco identified (unexpected cisco_tac_alarm.log and cisco_tac.log files in /tmp or /usr/binos/conf), and immediately report positive findings to CISA per BOD 23-02. Keep in mind that patching alone does not remove a root implant, so devices with evidence of compromise should be reimaged or otherwise cleaned per vendor instructions.

10.0100% KEV
  • Cisco IOS XE (Web UI feature)
  • Rockwell Automation Allen-Bradley Stratix 5200 firmware
  • Rockwell Automation Allen-Bradley Stratix 5800 firmware
large≈40,000–50,000 internet-exposed IOS XE devices at the time of disclosure (public scan data), within an IOS XE install base in the millions
CVE-2023-20273
Authenticated Command Injection (Root) in Cisco IOS XE Web UI

CVE-2023-20273 is an OS command injection flaw (CWE-78) in the web UI feature of Cisco IOS XE Software, caused by insufficient input validation. An authenticated, remote attacker triggers it by sending crafted input to the web UI, and a successful exploit injects commands that run on the underlying operating system with root privileges, yielding full device compromise (in the October 2023 mass-exploitation campaign it was typically chained with the unauthenticated CVE-2023-20198 to obtain initial access and install a persistent implant). Any Cisco IOS XE device with the web UI enabled and reachable from the internet or an untrusted network is affected; this data does not specify the affected release ranges, which are enumerated in Cisco's advisory. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-10-23 with BOD 23-02 response actions, EPSS is ~90% (100th percentile), and IOS XE edge devices remain recurring targets of Chinese-nexus espionage campaigns (e.g., Salt Typhoon activity against telecoms).

Do: Upgrade affected devices to a fixed IOS XE release per Cisco's advisory; as an interim mitigation, disable the HTTP/HTTPS server (ip http server / ip https server) or restrict Web UI access to trusted hosts only. Per BOD 23-02, hunt for compromise on any exposed device — check for unexpected level-15 local accounts and the implant.lua backdoor in flash memory — and immediately report positive findings to CISA.

7.290% KEV
  • Cisco IOS XE Software (Web UI feature)
mass≈100,000+ internet-exposed IOS XE devices (public scans observed ~40,000+ compromised within days of disclosure)
Full article952 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The Chinese nation-state threat group intruded five additional telecom networks between December and January, including two unnamed providers in the U.S., Recorded Future researchers said.

Listen to this article

0:00

Learn more.

For suspected Chinese hackers, U.S. telecoms represent a tempting target for espionage. (Getty Images)

Salt Typhoon, the Chinese nation-state threat group linked to a spree of attacks on U.S. and global telecom providers, remains active in its intrusion and has hit multiple additional networks worldwide, including two in the United States, Recorded Future said in a report released Thursday.

Recorded Future’s Insikt Group observed seven compromised Cisco network devices communicating with Salt Typhoon infrastructure on five telecom networks between early December and late January. The compromised companies include an unnamed U.S. internet service provider and telecom company, a U.S.-based affiliate of a U.K. telecom provider, a large telecom provider in Thailand, an Italy-based ISP and a South Africa-based telecom provider.

Salt Typhoon’s ongoing attack spree underscores the enduring challenge global cyber authorities and network defenders confront in trying to thwart the nation-state group’s activities. U.S. and White House officials in December warned they may never know if the group has been completely booted from networks. 

Attackers primarily targeted internet-exposed Cisco network routers over the past couple months, according to Recorded Future. Tracked as RedMike by the company, the group has attempted to exploit more than 1,000 Cisco routers worldwide — focusing mainly on those running in telecom networks — since early December.

The threat group exploited a pair of known privilege escalation vulnerabilities in Cisco IOS XE, the vendor’s operating system for networking devices, Recorded Future said in the report. 

Vulnerabilities in network devices are a common intrusion point for cyberattacks.

The pair of CVEs impacting Cisco IOS XE — CVE-2023-20198 and CVE-2023-20273 — were the third and fourth most routinely-exploited vulnerabilities in 2023, according to a Five Eyes cyber advisory released in November. 

In the attacks monitored by Recorded Future, Salt Typhoon chained multiple vulnerabilities together. First, it exploited CVE-2023-20198, a vulnerability with a 10 score on the CVSS scale, in order to create a local user and password on the targeted device. Using this new account, it then accessed the device and exploited CVE-2023-20273 to gain root user privileges.

“We have not observed other initial access vectors related to this campaign at this time,” Jon Condra, senior director of strategic intelligence at Recorded Future, said in an email. “We also have no indication that the previously publicized intrusions against AT&T, Verizon, etc. linked to Salt Typhoon were linked to these specific vulnerabilities or Cisco devices more broadly.”

Authorities haven’t identified the primary initial access point for Salt Typhoon’s attacks, but hardening guidance released by U.S. and global officials in December specifically called out the need for network defenders to address the risk of Cisco device exploitation. Officials didn’t mention specific vulnerabilities in the guidance, but advised organizations to refer to Cisco’s hardening guides for NX-OS software devices and IOS-XE.

“In 2023, Cisco published a security advisory disclosing multiple vulnerabilities in the web UI feature in Cisco IOS XE software,” a Cisco spokesperson said via email. “We continue to strongly urge customers to follow recommendations outlined in the advisory and upgrade to the available fixed software release.”

The majority of the Cisco devices targeted by Salt Typhoon since early December were used by telecom providers based in the U.S., South America and India, but other targeted devices were spread across more than 100 countries, according to Recorded Future. Researchers also observed Salt Typhoon attempting to exploit Cisco devices used by universities in nine countries, including four in the U.S., potentially targeting research related to telecom, engineering and technology.

Salt Typhoon’s attack spree targeting global telecom networks began up to two years before it was discovered by U.S. officials in late spring of last year. The Chinese nation-state threat group gained broad and full access to U.S. telecom networks, stole metadata, geolocated millions of individuals at will and directly targeted and stole communications of about 100 individuals involved in government or political activities.

Salt Typhoon is one of three known and active threat groups affiliated with China’s government. U.S. authorities have been warning about Chinese hacking efforts targeting critical infrastructure with increasing alarm since early 2024. 

Recorded Future’s research on the group’s ongoing activities follows a series of sanctions placed on China-based organizations and individuals for their alleged involvement in the telecom network attacks and a December hack of the Treasury Department.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/salt-typhoon-china-ongoing-telecom-attack-spree/