انتقل إلى المحتوى الرئيسي
English
logo
مستوى الخطورة: حرجة
ثغرة

الرقم المرجعي: NCSC-TAD-2607-002CVSS 0

Protecting Routers from State-Sponsored Cyber Threats

نوع التهديد:
غير متوفر
مستوى المشاركة (TLP):
CLEAR
CVE:
CVE-2018-0171, CVE-2008-4128

نظرة عامة

State-sponsored cyber actors are actively targeting insecure network devices by exploiting weak SNMP configurations, Cisco Smart Install (SMI), and known vulnerabilities, including CVE-2018-0171 and CVE-2008-4128, to gain unauthorized access and extract device configurations.

التقنيات المتأثرة

  • Cisco Smart Install (SMI)

إجراءات الحد من المخاطر والإجراءات الفورية

  1. 01

    Disable Cisco Smart Install (SMI) on all devices.

  2. 02

    Use SNMPv3 with authPriv and disable SNMPv1/v2.

  3. 03

    Enforce strong, unique passwords and securely manage credentials for all network devices.

  4. 04

    Restrict management protocols using ACLs and block unnecessary traffic on ports 69 (TFTP), 4786 (SMI), 161/162 (SNMP), and 10161/10162 (SNMPv3).

  5. 05

    Restrict SNMP OID access using a Management Information Base (MIB) allow list.

  6. 06

    Update network device software and firmware to the latest supported versions.

المراجع