CVE-2017-3881
published 2017-03-17CVE-2017-3881: A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
98.98%
99.9th percentile
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device. This affects Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 EtherSwitch Service Module, Gigabit Ethernet Switch Module (CGESM) for HP, IE Industrial Ethernet switches, ME 4924-10GE switch, RF Gateway 10, and SM-X Layer 2/3 EtherSwitch Service Module. Cisco Bug IDs: CSCvd48893.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | 12.2s – 15.1\(3\)svs | — |
| cisco | ios_and_ios_xe | — | — |
| cisco | ios_xe | 3.2sg – 3.9e | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit targets Telnet (TCP/23) by sending malformed CMP-specific Telnet options during session establishment; detect anomalous Telnet option negotiation sequences directed at Cisco IOS/IOS XE devices ↗
- →The modified CVE-2017-3881 Telnet exploit was used to enable arbitrary memory read/write on Cisco switches; monitor for unexpected Telnet sessions to management interfaces on Cisco Catalyst/IOS devices ↗
- →Hunt for hidden rogue local accounts matching the pattern dg[0-9]y[0-9][a-z]pk on Cisco device running configurations, as these are rootkit-created hidden accounts ↗
- →Hunt for hidden EEM scripts named CiscoEMX-1 through CiscoEMX-5 in Cisco device configurations; these are concealed by the rootkit and will not appear in standard 'show running-config' output ↗
- →Hunt for hidden ACLs named EnaQWklg0, EnaQWklg1, EnaQWklg2 in Cisco device configurations; these are concealed by the rootkit from standard running-config output ↗
- →Monitor for UDP traffic directed to any IP on a Cisco switch on non-standard/unexpected ports; the rootkit UDP controller accepts packets on any port regardless of whether it is open ↗
- →Alert on unexpected last running-config write timestamp resets on Cisco devices, which the rootkit uses to hide configuration changes ↗
- →Metasploit auxiliary module ios_telnet_rocem.rb targets this vulnerability against Cisco Catalyst 2960 and 3750; detect exploitation attempts using this module via IDS signatures on Telnet traffic ↗
- ·The vulnerability only affects Cisco IOS/IOS XE devices that are configured to accept Telnet connections; devices with Telnet disabled are not exploitable via this vector ↗
- ·The in-the-wild exploitation of CVE-2017-3881 observed in Operation Zero Disco is a modified variant that enables memory read/write rather than the original RCE/DoS; detection rules tuned only for the original exploit behavior may miss this modified version ↗
- ·Rootkit hooks into IOSd memory result in fileless components that disappear after reboot, meaning post-reboot forensics may not reveal compromise; low-level firmware and ROM region investigation is required ↗
- ·Newer Cisco switch models with ASLR are more resistant but not immune; repeated exploitation attempts can still succeed ↗
- ·There is currently no universal automated tool that can reliably determine whether a Cisco switch has been successfully compromised by this operation ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS and IOS XE Remote Code Execution Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2017-3881 [CRITICAL] CWE-20 Cisco IOS and IOS XE Remote Code Execution Vulnerability
Vulnerability: Cisco IOS and IOS XE Remote Code Execution Vulnerability
Affected: Cisco IOS and IOS XE
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-3881
Remediation Due Date: 2022-04-15
CISA ICS
Rockwell Automation Allen-Bradley Stratix and Allen-Bradley ArmorStratix
cisa_ics·2017-04-04
Rockwell Automation Allen-Bradley Stratix and Allen-Bradley ArmorStratix
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Allen-Bradley Stratix and Allen-Bradley ArmorStratix
Last RevisedApril 04, 2017
Alert CodeICSA-17-094-03
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Allen-Bradley Stratix, Allen-Bradley ArmorStratix
Vulnerability: Improper Input Validation
## AFFECTED PRODUCTS
The following versions of the Allen-Bradley Stratix and ArmorStratix Industrial Ethernet and Distribution switches are affected:
- Allen-Bradley Stratix 5400 Industrial Ethernet Switches, All Versions 15.2(5)EA.fc4 and earlier,
Cisco
Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability
vendor_cisco·2017-03-17·CVSS 9.8
CVE-2017-3881 [CRITICAL] Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability
Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors:
The failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device, and
The incorrect processing of malformed CMP-
Cisco
Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3881 Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability
CVE-2017-3881: Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: The failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device, and The incorrect processing of ma
GHSA
GHSA-g37w-qg7v-7fjq: A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated,
ghsa_unreviewed·2022-05-13
CVE-2017-3881 [CRITICAL] CWE-20 GHSA-g37w-qg7v-7fjq: A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated,
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker could exploit this vulnerability by sending malforme
VulnCheck
Cisco IOS and IOS XE Remote Code Execution Vulnerability
vulncheck·2017·CVSS 9.8
CVE-2017-3881 [CRITICAL] CWE-20 Cisco IOS and IOS XE Remote Code Execution Vulnerability
Cisco IOS and IOS XE Remote Code Execution Vulnerability
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
Affected: Cisco IOS and IOS XE Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.alertlogic.com/blog/ironically-positive-fallout-from-vault-7-cisco-vault-7-cve-2017-3881-d48/; https://blog.talosintelligence.com/2019/04/seaturtle.html; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.trendmic
Suricata
ET EXPLOIT Cisco Catalyst Remote Code Execution (CVE-2017-3881)
suricata·2017-04-10·CVSS 9.8
CVE-2017-3881 [CRITICAL] ET EXPLOIT Cisco Catalyst Remote Code Execution (CVE-2017-3881)
ET EXPLOIT Cisco Catalyst Remote Code Execution (CVE-2017-3881)
Rule: alert tcp any any -> $HOME_NET 23 (msg:"ET EXPLOIT Cisco Catalyst Remote Code Execution (CVE-2017-3881)"; flow:established,to_server; content:"|ff fa 24 00 03|CISCO_KITS"; content:"|3a|"; distance:2; within:1; isdataat:160,relative; content:!"|3a|"; within:160; reference:url,artkond.com/2017/04/10/cisco-catalyst-remote-code-execution/; classtype:attempted-user; sid:2024194; rev:2; metadata:affected_product CISCO_Catalyst, attack_target IoT, created_at 2017_04_10, cve CVE_2017_3881, deployment Datacenter, performance_impact Low, confidence Medium, signature_severity Critical, tag CISA_KEV, updated_at 2024_03_07, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Explo
Exploit-DB
Cisco Catalyst 2960 IOS 12.2(55)SE11 - 'ROCEM' Remote Code Execution
exploitdb·2017-04-12·CVSS 9.8
CVE-2017-3881 [CRITICAL] Cisco Catalyst 2960 IOS 12.2(55)SE11 - 'ROCEM' Remote Code Execution
Cisco Catalyst 2960 IOS 12.2(55)SE11 - 'ROCEM' Remote Code Execution
---
#!/usr/bin/python
# Exploit Title: Cisco Catalyst 2960 - Buffer Overflow
# Exploit Details: https://artkond.com/2017/04/10/cisco-catalyst-remote-code-execution/
# Date: 04.10.2017
# Exploit Author: https://twitter.com/artkond
# Vendor Homepage: https://www.cisco.com/
# Version: IOS version c2960-lanbasek9-mz.122-55.SE11)
# Tested on: Catalyst 2960 with IOS version c2960-lanbasek9-mz.122-55.SE11
# CVE : CVE-2017-3881
# Description:
#
# The exploit connects to the Catalyst switch and patches
# it execution flow to allow credless telnet interaction
# with highest privilege level
#
import socket
import sys
from time import sleep
set_credless = True
if len(sys.argv) < 3:
print sys.argv[0] + ' [host] --set/--unset'
sy
Exploit-DB
Cisco Catalyst 2960 IOS 12.2(55)SE1 - 'ROCEM' Remote Code Execution
exploitdb·2017-04-12
CVE-2017-3881 Cisco Catalyst 2960 IOS 12.2(55)SE1 - 'ROCEM' Remote Code Execution
Cisco Catalyst 2960 IOS 12.2(55)SE1 - 'ROCEM' Remote Code Execution
---
#!/usr/bin/python
# Author:
# Artem Kondratenko (@artkond)
import socket
import sys
from time import sleep
set_credless = True
if len(sys.argv) < 3:
print sys.argv[0] + ' [host] --set/--unset'
sys.exit()
elif sys.argv[2] == '--unset':
set_credless = False
elif sys.argv[2] == '--set':
pass
else:
print sys.argv[0] + ' [host] --set/--unset'
sys.exit()
s = socket.socket( socket.AF_INET, socket.SOCK_STREAM)
s.connect((sys.argv[1], 23))
print '[+] Connection OK'
print '[+] Recieved bytes from telnet service:', repr(s.recv(1024))
#sleep(0.5)
print '[+] Sending cluster option'
print '[+] Setting credless privilege 15 authentication' if set_credless else '[+] Unsetting credless privilege 15 authentication'
payload =
Metasploit
Cisco IOS Telnet Denial of Service
metasploit
Cisco IOS Telnet Denial of Service
Cisco IOS Telnet Denial of Service
This module triggers a Denial of Service condition in the Cisco IOS telnet service affecting multiple Cisco switches. Tested against Cisco Catalyst 2960 and 3750.
Nuclei
Cisco IOS 12.2(55)SE11 - Remote Code Execution
nuclei·CVSS 9.8
CVE-2017-3881 [CRITICAL] Cisco IOS 12.2(55)SE11 - Remote Code Execution
Cisco IOS 12.2(55)SE11 - Remote Code Execution
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker coul
Bleepingcomputer
Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
blogs_bleepingcomputer·2025-10-16·CVSS 9.8
CVE-2025-20352 [CRITICAL] Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
## Hackers exploit Cisco SNMP flaw to deploy rootkit on switches
## Bill Toulas
Threat actors exploited a recently patched remote code execution vulnerability (CVE-2025-20352) in Cisco networking devices to deploy a rootkit and target unprotected Linux systems.
The security issue leveraged in the attacks affects the Simple Network Management Protocol (SNMP) in Cisco IOS and IOS XE and leads to RCE if the attacker has root privileges.
According to cybersecurity company Trend Micro, the attacks exploited the flaw in Cisco 9400, 9300, and legacy 3750G series devices and deployed rootkits on "older Linux systems that do not have endpoint detection response solutions."
In the original bulletin for CVE-2025-20352, updated on October 6, Cisco tagged the vulnerability as exploited as a zero d
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Exploits & Vulnerabilities
## Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang Oct 15, 2025 Read time: ( words)
Save to Folio
Key takeaways:
Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorised access by setting universal passwords and installing hooks into IOSd memory space.
The operation primarily impacted Cisco 9400, 9300, and legacy 3750G
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Exploits & Vulnerabilities
# Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang
2025/10/15
Read time: ( words)
Save to Folio
Key takeaways:
- Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorized access by setting universal passwords and installing hooks into IOSd memory space.
- The operation primarily impacted Cisco 9400, 9300, and legacy 3750
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Exploits y vulnerabilidades
## Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang Oct 15, 2025 Read time: ( words)
Save to Folio
Key takeaways:
Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorized access by setting universal passwords and installing hooks into IOSd memory space.
The operation primarily impacted Cisco 9400, 9300, and legacy 3750
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Exploits & Vulnerabilities
## Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang 2025/10/15 Read time: ( words)
Save to Folio
Key takeaways:
Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorized access by setting universal passwords and installing hooks into IOSd memory space.
The operation primarily impacted Cisco 9400, 9300, and legacy 3750G s
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Exploits & Vulnerabilities
## Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang Oct 15, 2025 Read time: ( words)
Save to Folio
Key takeaways:
Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorized access by setting universal passwords and installing hooks into IOSd memory space.
The operation primarily impacted Cisco 9400, 9300, and legacy 3750G
Trendmicro
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
blogs_trendmicro·2025-10-15·CVSS 9.8
CVE-2025-20352 [CRITICAL] Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Ausnutzung von Schwachstellen
## Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Trend™ Research has uncovered an attack campaign exploiting the Cisco SNMP vulnerability CVE-2025-20352, allowing remote code execution and rootkit deployment on unprotected devices, with impacts observed on Cisco 9400, 9300, and legacy 3750G series.
By: Dove Chiu, Lucien Chuang Oct 15, 2025 Read time: ( words)
Save to Folio
Key takeaways:
Attackers exploited the Cisco SNMP vulnerability (CVE-2025-20352) to deploy Linux rootkits on older, unprotected systems, allowing remote code execution (RCE) and persistent unauthorized access by setting universal passwords and installing hooks into IOSd memory space.
The operation primarily impacted Cisco 9400, 9300, and legacy 37
Tenable
Sea Turtle DNS Hijacking Campaign Utilizes At Least Seven Patched Vulnerabilities
blogs_tenable·2019-04-19
Sea Turtle DNS Hijacking Campaign Utilizes At Least Seven Patched Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
DNS Hijacking Abuses Trust In Core Internet Service
blogs_talos·2019-04-17
DNS Hijacking Abuses Trust In Core Internet Service
By Danny Adamitis, David Maynor, Warren Mercer, Matthew Olney and Paul Rascagneres.
Update 4/18: A correction has been made to our research based on feedback from Packet Clearing House, we thank them for their assistance
## Preface
This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily national security organizations in the Middle East and North Africa, and we do not want to overstate the consequences of this specific campaign, we are concerned that the success of this operation will lead to actors more broadly attacking the global DNS system. DNS is a foundational technology supporting the Internet. Manipulating that system has the potential to undermine the trust users have on the inter
Talos
DNS Hijacking Abuses Trust In Core Internet Service
blogs_talos·2019-04-17
DNS Hijacking Abuses Trust In Core Internet Service
## DNS Hijacking Abuses Trust In Core Internet Service
By Danny Adamitis , David Maynor , Warren Mercer , Matthew Olney and Paul Rascagneres . Update 4/18: A correction has been made to our research based on feedback from Packet Clearing House, we thank them for their assistance
## Preface
This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily national security organizations in the Middle East and North Africa, and we do not want to overstate the consequences of this specific campaign, we are concerned that the success of this operation will lead to actors more broadly attacking the global DNS system. DNS is a foundational technology supporting the Internet. Manipulating that system has t
http://www.securityfocus.com/bid/96960http://www.securityfocus.com/bid/97391http://www.securitytracker.com/id/1038059https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmphttps://www.exploit-db.com/exploits/41872/https://www.exploit-db.com/exploits/41874/http://www.securityfocus.com/bid/96960http://www.securityfocus.com/bid/97391http://www.securitytracker.com/id/1038059https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmphttps://www.exploit-db.com/exploits/41872/https://www.exploit-db.com/exploits/41874/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-3881
2017-03-17
Published
2022-03-25
Added to CISA KEV
Exploited in the wild