A Russian state-sponsored threat group, Static Tundra, is exploiting an old Cisco vulnerability (CVE-2018-0171) to access and manipulate network configurations globally. The FBI and Cisco warn that these attacks target critical infrastructure and have persisted since 2015, mainly affecting legacy devices with unpatched firmware. #CVE2018-0171 #StaticTundra
Keypoints
- The FBI warns of ongoing exploitation of Ciscoβs CVE-2018-0171 vulnerability by Russian hackers.
- Static Tundra, a subgroup within Energetic Bear, has targeted globally distributed networking devices since 2015.
- Attacks include harvesting configuration data and using malware like SYNful Knock for persistent access.
- Organizations are advised to patch affected devices or disable the Smart Install feature to prevent breaches.
- The threat actors mainly focus on critical infrastructures, telecoms, and manufacturing sectors in Russia and allied countries.
Read More: https://www.securityweek.com/russian-apt-exploiting-7-year-old-cisco-vulnerability-fbi/