ZeroHour
The Recordpublished ()ingested

CISA, Cisco highlight Russian military targeting of router vulnerabilities

mediumVulnerabilityimportance 35CVE-2017-6742

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-6742
Authenticated SNMP Remote Code Execution in Cisco IOS and IOS XE Software

CVE-2017-6742 is a memory-corruption flaw (CWE-119) in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE. It is triggered when an affected device processes crafted SNMP packets sent by an authenticated, remote attacker, meaning the device must have SNMP enabled and the attacker must hold valid SNMP credentials or community strings. Successful exploitation lets the attacker execute code on the router or switch, or force the device to reload, yielding either full control of the device or a denial of service on critical network infrastructure. Any organization running vulnerable Cisco IOS or IOS XE releases with SNMP enabled on routers, switches, or other network devices is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2023-04-19), confirming in-the-wild exploitation; EPSS estimates a 21.4% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept code is known.

Do: Upgrade affected Cisco IOS and IOS XE devices to fixed releases per Cisco's advisory, prioritizing internet-facing routers and switches as the KEV listing makes patching mandatory for federal agencies and urgent for others. As interim mitigation, restrict SNMP access to trusted management hosts with ACLs, disable SNMP entirely where it is not required, and rotate SNMP community strings/credentials that could be used for authentication. Inventory devices for enabled SNMP services and vulnerable releases, focusing first on edge and internet-exposed infrastructure.

8.821% KEV
  • Cisco IOS
  • Cisco IOS XE Software
masson the order of hundreds of thousands of systems (well above 100k affected/exposed devices, given Cisco's installed base)
Full article669 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency and technology giant Cisco released advisories on Tuesday spotlighting attacks on routers allegedly being exploited by Russian military hackers.

In its report, CISA was joined by the FBI, NSA and the UK National Cyber Security Centre (NCSC) in highlighting the actions of APT28 – which the agencies believe is the Russian General Staff Main Intelligence Directorate’s (GRU) 85th special Service Centre (GTsSS) Military Intelligence Unit 26165.

Known among researchers as Fancy Bear and STRONTIUM, the group allegedly exploited Cisco router vulnerabilities throughout 2021, attacking “a small number based in Europe, US government institutions and approximately 250 Ukrainian victims.”

NCSC previously attributed attacks on the German parliament in 2015 and the Organization for the Prohibition of Chemical Weapons (OPCW) in April 2018 to APT28.

The advisory says the group used two different attacks to target Cisco routers. One involves the exploitation of Simple Network Management protocol (SNMP) – a tool that allows network administrators to monitor and configure network devices remotely. The tools can be abused to steal sensitive network information and subsequently penetrate a network, CISA said.

“A number of software tools can scan the entire network using SNMP, meaning that poor configuration such as using default or easy-to-guess community strings, can make a network susceptible to attacks,” CISA explained. “Weak SNMP community strings, including the default ‘public,’ allowed APT28 to gain access to router information.”

The hackers also exploited CVE-2017-6742, an SNMP vulnerability patched by Cisco in June 2017.

Cisco's advisory at the time provided several workarounds that included limiting access to SNMP from trusted hosts only, or by disabling a number of SNMP Management Information bases (MIBs).

CISA said APT28 used malware to exploit SNMP to obtain device information and exfiltrate data. The NCSC called this malware campaign “Jaguar Tooth” and Cisco’s Matt Olney said it was an “example of a much broader trend of sophisticated adversaries targeting networking infrastructure to advance espionage objectives or pre-position for future destructive activity.”

“While infrastructure of all types has been observed under attack, attackers have been particularly successful in compromising infrastructure with out-of-date software,” Olney said. “Cisco is deeply concerned by an increase in the rate of high-sophistication attacks on network infrastructure — that we have observed and have seen corroborated by numerous reports issued by various intelligence organizations — indicating state-sponsored actors are targeting routers and firewalls globally.”

Olney explained in a blog post that in addition to Russia, China has also been spotted attacking network equipment in several campaigns.

A Cisco spokesperson said the company continues to observe a rising volume of attacks against particularly out-of-date networking appliances and software across all vendors.

“Today's alert demonstrates that sophisticated adversaries are systematically taking advantage of known vulnerabilities, in this case an SNMP vulnerability in Cisco IOS and Cisco IOS XE Software that was disclosed by Cisco on June 29, 2017, with fixed software made available to all customers that same day,” the spokesperson said.

APT28 has long been one of the most prolific military hacking groups operating out of Russia, launching dozens of disinformation and government hacking campaigns in recent years. The group has often relied on spear-phishing emails to go after targets of interest – with several companies spotlighting their work.

ATP28 has been involved in a number of cyberattacks in which they have stolen highly sensitive information about topics including the conflict in Syria, NATO-Ukraine relations, the European Union refugee and migrant crisis, the 2016 Olympics and Paralympics Russian athlete doping scandal, public accusations regarding Russian state-sponsored hacking, and the 2016 U.S. presidential election, according to a report by Mandiant.

ATP28 was also linked to the cyberattack on U.S. satellite communications provider Viasat.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-cisco-russia-military-hackers-routers