Skip to main content
عربي
logo

NCSC-TAD-2607-002

Severity Level: Critical
Vulnerability

Reference No.: NCSC-TAD-2607-002CVSS 0

Protecting Routers from State-Sponsored Cyber Threats

Threat Type:
N/A
TLP:
CLEAR
CVE:
CVE-2018-0171, CVE-2008-4128

Overview

State-sponsored cyber actors are actively targeting insecure network devices by exploiting weak SNMP configurations, Cisco Smart Install (SMI), and known vulnerabilities, including CVE-2018-0171 and CVE-2008-4128, to gain unauthorized access and extract device configurations.

Affected Technologies

  • Cisco Smart Install (SMI)

Mitigation and Immediate Actions

  1. 01

    Disable Cisco Smart Install (SMI) on all devices.

  2. 02

    Use SNMPv3 with authPriv and disable SNMPv1/v2.

  3. 03

    Enforce strong, unique passwords and securely manage credentials for all network devices.

  4. 04

    Restrict management protocols using ACLs and block unnecessary traffic on ports 69 (TFTP), 4786 (SMI), 161/162 (SNMP), and 10161/10162 (SNMPv3).

  5. 05

    Restrict SNMP OID access using a Management Information Base (MIB) allow list.

  6. 06

    Update network device software and firmware to the latest supported versions.

References