
- الصفحة الرئيسية
- نشرات التهديدات
- NCSC-TAD-2607-002
NCSC-TAD-2607-002
الرقم المرجعي: NCSC-TAD-2607-002CVSS 0
Protecting Routers from State-Sponsored Cyber Threats
- نوع التهديد:
- غير متوفر
- مستوى المشاركة (TLP):
- CLEAR
- CVE:
- CVE-2018-0171, CVE-2008-4128
نظرة عامة
State-sponsored cyber actors are actively targeting insecure network devices by exploiting weak SNMP configurations, Cisco Smart Install (SMI), and known vulnerabilities, including CVE-2018-0171 and CVE-2008-4128, to gain unauthorized access and extract device configurations.
التقنيات المتأثرة
- Cisco Smart Install (SMI)
إجراءات الحد من المخاطر والإجراءات الفورية
- 01
Disable Cisco Smart Install (SMI) on all devices.
- 02
Use SNMPv3 with authPriv and disable SNMPv1/v2.
- 03
Enforce strong, unique passwords and securely manage credentials for all network devices.
- 04
Restrict management protocols using ACLs and block unnecessary traffic on ports 69 (TFTP), 4786 (SMI), 161/162 (SNMP), and 10161/10162 (SNMPv3).
- 05
Restrict SNMP OID access using a Management Information Base (MIB) allow list.
- 06
Update network device software and firmware to the latest supported versions.

