Improve Router Hygiene to Prot... Note

Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting

The Russian Federal Security Service (FSB) Center 16 cyber actors are targeting poorly configured and vulnerable networking devices worldwide, compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory provides additional tactics, techniques, and procedures to enable defenders to understand and counter the threat. The advisory is being released by multiple authoring and co-sealing agencies, including the United States National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation. The agencies strongly urge device owners and network defenders to take mitigation and remediation actions against Russian government-sponsored exploitation of vulnerable routers. The targeted critical infrastructure sectors include communications, defense industrial base, energy, financial services, government services, and healthcare. The Russian FSB Center 16 cyber actors primarily use scanning to identify poorly configured networking devices, primarily routers, for exploitation. The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication. To mitigate these threats, the authoring agencies recommend implementing several measures, including disabling Cisco Smart Install, using SNMPv3 with strong authentication and encryption, and restricting management protocols. The agencies also recommend monitoring for unusual credentials, restricting access to SNMP OIDs, and updating network device software and firmware images to patch known vulnerabilities.
CdXz5zHNQW_THjX5Y5Y9e.png