Russian state-sponsored attacks continue to exploit “poorly configured and vulnerable networking devices worldwide,” potentially compromising critical infrastructure, warns a recent multinational cybersecurity advisory.
The advisory — jointly issued by the US National Security Agency (NSA), CISA, and FBI, along with security and intelligence agencies across Europe, New Zealand, and Australia — strongly urges device owners and administrators to take the following recommended steps to secure routers against these attacks:
- Disable Cisco Smart Install on all devices. The advisory notes that this feature is designed for initial router configuration and can introduce security risks if left enabled.
- Implement SNMPv3 with “authPriv” configured to the most modern encryption standard that is supported by the device.
- Use strong, unique passwords on network devices and configure credentials to be stored securely to prevent reuse of compromised passwords. On Cisco devices, use hashing type 8 for user credentials; avoid type 0, 4, and 7.
- Deny inbound and outbound traffic on UDP port 69 (TFTP), TCP port 4786 (SMI), UDP ports 161 and 162 (SNMP), TCP/UDP ports 10161 and 10162 (SNMPv3) for all edge firewalls and devices.
Critical infrastructure sectors most at risk from these Russian state-sponsored attacks include:
- Communications
- Defense industrial base
- Energy
- Financial services
- State and local government services and facilities
- Healthcare and public health systems
Learn more about these attacks and get additional technical details from the official CISA advisory.