U.S. and U.K. Warn of Russian Hackers Exploiting Cisco Router Flaws for Espionage
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-6742 | Authenticated SNMP Remote Code Execution in Cisco IOS and IOS XE Software CVE-2017-6742 is a memory-corruption flaw (CWE-119) in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE. It is triggered when an affected device processes crafted SNMP packets sent by an authenticated, remote attacker, meaning the device must have SNMP enabled and the attacker must hold valid SNMP credentials or community strings. Successful exploitation lets the attacker execute code on the router or switch, or force the device to reload, yielding either full control of the device or a denial of service on critical network infrastructure. Any organization running vulnerable Cisco IOS or IOS XE releases with SNMP enabled on routers, switches, or other network devices is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2023-04-19), confirming in-the-wild exploitation; EPSS estimates a 21.4% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept code is known. Do: Upgrade affected Cisco IOS and IOS XE devices to fixed releases per Cisco's advisory, prioritizing internet-facing routers and switches as the KEV listing makes patching mandatory for federal agencies and urgent for others. As interim mitigation, restrict SNMP access to trusted management hosts with ACLs, disable SNMP entirely where it is not required, and rotate SNMP community strings/credentials that could be used for authentication. Inventory devices for enabled SNMP services and vulnerable releases, focusing first on edge and internet-exposed infrastructure. | 8.8 | 21% | KEV |
| masson the order of hundreds of thousands of systems (well above 100k affected/exposed devices, given Cisco's installed base) |
Full article524 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 19, 2023Network Security / Cyber Espionage
U.K. and U.S. cybersecurity and intelligence agencies have warned of Russian nation-state actors exploiting now-patched flaws in networking equipment from Cisco to conduct reconnaissance and deploy malware against select targets.
The intrusions, per the authorities, took place in 2021 and targeted a small number of entities in Europe, U.S. government institutions, and about 250 Ukrainian victims.
The activity has been attributed to a threat actor tracked as APT28, which is also known as Fancy Bear, Forest Blizzard (formerly Strontium), FROZENLAKE, and Sofacy, and is affiliated with the Russian General Staff Main Intelligence Directorate (GRU).
"APT28 has been known to access vulnerable routers by using default and weak SNMP community strings, and by exploiting CVE-2017-6742," the National Cyber Security Centre (NCSC) said.
CVE-2017-6742 (CVSS score: 8.8) is part of a set of remote code execution flaws that stem from a buffer overflow condition in the Simple Network Management Protocol (SNMP) subsystem in Cisco IOS and IOS XE software.
In the attacks observed by the agencies, the threat actor weaponized the vulnerability to deploy a non-persistent malware dubbed Jaguar Tooth on Cisco routers that's capable of gathering device information and enabling unauthenticated backdoor access.
While the issues were patched by Cisco in June 2017, they have since come under public exploitation as of January 11, 2018, underscoring the need for robust patch management practices to limit the attack surface.
Besides updating to the latest firmware to mitigate potential threats, the company is also recommending that users switch from SNMP to NETCONF or RESTCONF for network management.
Cisco Talos, in a coordinated advisory, said the attacks are part of a broader campaign against aging networking appliances and software from a variety of vendors to "advance espionage objectives or pre-position for future destructive activity."
This includes the installation of malicious software into an infrastructure device, attempts to surveil network traffic, and attacks mounted by "adversaries with preexisting access to internal environments targeting TACACS+/RADIUS servers to obtain credentials."
"Route/switch devices are stable, infrequently examined from a security perspective, are often poorly patched and provide deep network visibility," Matt Olney, director of threat intelligence and interdiction at Cisco, said.
"They are the perfect target for an adversary looking to be both quiet and have access to important intelligence capability as well as a foothold in a preferred network. National intelligence agencies and state-sponsored actors across the globe have attacked network infrastructure as a target of primary preference."
The alert comes months after the U.S. government sounded the alarm about China-based nation-state hacking crews leveraging network vulnerabilities to exploit public and private sector organizations since at least 2020.
Then earlier this year, Google-owned Mandiant highlighted efforts undertaken by Chinese state-sponsored threat actors to deploy bespoke malware on vulnerable Fortinet and SonicWall devices.
"Advanced cyber espionage threat actors are taking advantage of any technology available to persist and traverse a target environment, especially those technologies that do not support [endpoint detection and response] solutions," Mandiant said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/04/us-and-uk-warn-of-russian-hackers.html