The US IT security authority CISA warns of currently observed attacks on a Cisco IOS vulnerability that is already 18 years old. Together with numerous international IT security authorities, CISA has also published a guide to help secure routers against attacks, particularly from state actors from Russia.
The CISA IT security officials have now added the Cisco IOS security vulnerability to the "Known Exploited Vulnerabilities" catalog. It is a "Cross-Site Request Forgery" vulnerability, where a malicious website tricks the browser of logged-in users into performing actions on behalf of the attackers on the vulnerable website. Cisco IOS 12.4's web management interface is affected. The vulnerability has been known since 2008 and was already fixed at the time ( CVE-2008-4128 , CVSS 4.3 , risk " medium ").
CISA does not specify the extent of the attacks or their specific nature, as is usual. However, IT managers should check if they are still using vulnerable devices and update them if possible, or replace them with devices and software versions still supported by the manufacturer.
The attacks may originate from circles associated with Russia. Together with numerous other international law enforcement and IT security authorities, CISA issued a guide on Monday of this week to help admins protect routers from attacks by Russian state actors.
Members of "Center 16" of the Russian secret service FSB, in particular, are attacking poorly configured and vulnerable network devices globally and opportunistically compromising various critical infrastructure networks. A graphic contrasts the agents' actions with countermeasures, such as implementing SNMPv3 instead of the vulnerable and less secure versions SNMPv1 and SNMPv2. Secure passwords should also be used. Admins should also disable Cisco's "Smart Install" and block SNMP, TFTP, and SMI traffic on the firewall. A PDF file goes into a bit more detail and explicitly mentions the Cisco IOS vulnerability now reported as attacked, as well as the previously exploited Smart Install vulnerability CVE-2018-0171.
Vulnerabilities in Cisco products are highly popular among cybercriminals, as they regularly provide access to networks. Most recently, for example, attacks on Cisco's Unified CM were observed at the end of June .
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
