Russian APT Exploiting 7-Year-Old Cisco Vulnerability: FBI

Russian APT Exploiting 7-Year-Old Cisco Vulnerability: FBI

A Russian state-sponsored threat group, Static Tundra, is exploiting an old Cisco vulnerability (CVE-2018-0171) to access and manipulate network configurations globally. The FBI and Cisco warn that these attacks target critical infrastructure and have persisted since 2015, mainly affecting legacy devices with unpatched firmware. #CVE2018-0171 #StaticTundra

Keypoints

  • The FBI warns of ongoing exploitation of Cisco’s CVE-2018-0171 vulnerability by Russian hackers.
  • Static Tundra, a subgroup within Energetic Bear, has targeted globally distributed networking devices since 2015.
  • Attacks include harvesting configuration data and using malware like SYNful Knock for persistent access.
  • Organizations are advised to patch affected devices or disable the Smart Install feature to prevent breaches.
  • The threat actors mainly focus on critical infrastructures, telecoms, and manufacturing sectors in Russia and allied countries.

Read More: https://www.securityweek.com/russian-apt-exploiting-7-year-old-cisco-vulnerability-fbi/