FBI warns Russian hackers are targeting an old Cisco security flaw, so patch now
- The FBI has warned of Russian hackers abusing CVE-2018-0171
- Configuration files from “thousands” of Cisco devices were already stolen
- The bug affects many outdated endpoints, so patch now
Russian state-sponsored threat actors are abusing a years-old Cisco vulnerability to spy on organizations in the West, the FBI is warning.
In a public service announcement posted on the IC3 website, the FBI said it saw Center 16 – a threat actor linked to the Russian Federal Security Service (FSB) – exploiting Simple Network Management Protocol (SNMP), and a vulnerability in Cisco Smart Install (SMI) instances that reached end-of-life status.
The goal, the agency says, is to “broadly target entities in the United States and globally”.
End of life
The vulnerability being exploited here is tracked as CVE-2018-0171. Discovered roughly seven years ago, this improper validation of packet data flaw in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software allows unauthenticated, remote adversaries, to trigger a reload of an affected device, resulting in either arbitrary code execution, or a denial of service (DoS) condition.
The bug affected a wide range of Cisco Catalyst switches, including models from the Catalyst 2000, 3000, 3650, 3850, 4500, and 9000 series.
Cisco Industrial Ethernet switches, as well as some Nexus data center switches that had Smart Install enabled by default, were also affected.
Many of the older devices (Catalyst 2960, 3560, 3750, 4500E) have reached end-of-life, meaning they were never patched for this bug and remain vulnerable. Cisco advises users to replace them with newer models, such as those from the Catalyst 9000 series, which remain active product lines.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Over the past year, the FBI saw Center 16 collect configuration files for “thousands” of networking devices from US entities, mostly in the critical infrastructure sector.
“On some vulnerable devices, the actors modified configuration files to enable unauthorized access to those devices,” the FBI explained.
“The actors used the unauthorized access to conduct reconnaissance in the victim networks, which revealed their interest in protocols and applications commonly associated with industrial control systems.”
Via The Register
You might also like
The FBI has warned of Russian hackers abusing CVE-2018-0171 Configuration files from “thousands” of Cisco devices were already stolen The bug affects many outdated endpoints, so patch now Russian state-sponsored threat actors are abusing a years-old Cisco vulnerability to spy on organizations in the West, the FBI is warning. In…
Recent Posts
- LG Promo Codes and Coupons for June 2026
- 30% Off Canon Promo Codes | June 2026
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023