CVE-2018-0171
published 2018-03-28CVE-2018-0171: A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.51%
99.9th percentile
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios_and_ios_xe | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for inbound TCP connections to port 4786 (Cisco Smart Install) from untrusted/external sources; crafted Smart Install messages on this port are the exploit vector for CVE-2018-0171. ↗
- →Detect SNMP traffic with community strings 'anonymous' or 'public' with read-write permissions, which Static Tundra has used for initial access and lateral movement. ↗
- →Look for SSH daemons started on non-standard high ports (e.g., port 57722) within Cisco Guest Shell or underlying Linux shell, indicating persistent backdoor access. ↗
- →Monitor for the presence of a GO-compiled ELF x86-64 binary (JumbledPath) in actor-configured Guestshell instances on Cisco Nexus devices; this tool performs remote packet capture and log clearing. ↗
- →Monitor syslog and AAA logs for gaps or decreases in normal logging events, which may indicate the threat actor is clearing logs (.bash_history, auth.log, lastlog, wtmp, btmp) to cover tracks. ↗
- →Detect unexpected AAA/TACACS+ server IP address changes in device running configurations, which the threat actor uses to bypass access control systems. ↗
- →Use Tenable plugin 105161 to detect Cisco devices with Smart Install enabled and exposed on the network. ↗
- →Profile Cisco network devices via NetFlow and port scanning for new ports opening (especially non-standard SSH ports) or unexpected traffic sourced from loopback interfaces, which the threat actor modifies to bypass ACLs. ↗
- ·CVE-2018-0171 exploitation was confirmed in only one Salt Typhoon incident by Cisco Talos; all other Salt Typhoon initial accesses investigated used stolen legitimate credentials, not this CVE. ↗
- ·GreyNoise explicitly does not attribute the two malicious IPs exploiting CVE-2018-0171 to Salt Typhoon — only confirming exploitation is occurring. ↗
- ·Static Tundra (Russian FSB-linked) exploitation of CVE-2018-0171 is assessed with moderate confidence to use bespoke automated tooling against target IPs likely sourced from Shodan or Censys scan data. ↗
- ·Cisco Talos has not identified evidence confirming Salt Typhoon abused CVE-2023-20198, CVE-2023-20273, or CVE-2024-20399 beyond CVE-2018-0171, despite public reports claiming otherwise. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4w6g-87mh-x63x: A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigge
ghsa_unreviewed·2022-05-13
CVE-2018-0171 [CRITICAL] CWE-20 GHSA-4w6g-87mh-x63x: A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigge
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco
VulnCheck
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
vulncheck·2018·CVSS 9.8
CVE-2018-0171 [CRITICAL] CWE-20 Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
Affected: Cisco IOS and IOS XE Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://cisa.gov/news-events/alerts/2022/04/27/2021-top-routinely-exploited-vulnerabilities; https://cisa.gov/news-events/cybersecurity-advisories/aa22-117a; https://www.cisa.gov/uscert/ncas/alerts/aa22-158a; https://cisa.gov/news-events/cybersecurity-advisories/aa
CISA
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2018-0171 [CRITICAL] CWE-20 Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Vulnerability: Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Affected: Cisco IOS and IOS XE
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0171
Remediation Due Date: 2022-05-03
CISA ICS
Rockwell Automation Stratix Industrial Managed Ethernet Switch
cisa_ics·2018-04-25·CVSS 9.8
[CRITICAL] Rockwell Automation Stratix Industrial Managed Ethernet Switch
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix Industrial Managed Ethernet Switch
Last RevisedApril 25, 2018
Alert CodeICSA-18-107-05
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix Industrial Managed Ethernet Switch
- Vulnerabilities: Improper Input Validation, Resource Management Errors, 7PK – Errors, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use of Externally-Controlled Format String.
## 2. RISK EVALUATION
Successful exploitation of these vuln
CISA ICS
Rockwell Automation Stratix and ArmorStratix Switches
cisa_ics·2018-04-25
Rockwell Automation Stratix and ArmorStratix Switches
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix and ArmorStratix Switches
Last RevisedApril 25, 2018
Alert CodeICSA-18-107-04
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix and ArmorStratix Switches
- Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use of Externally-Controlled Format String.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in loss
Cisco
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
vendor_cisco·2018-03-28·CVSS 9.8
CVE-2018-0171 [CRITICAL] CWE-787 Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Update August 20, 2025: Cisco is aware of continued exploitation activity of the vulnerability that is described in this advisory and strongly recommends that customers assess their systems and upgrade to a fixed software release as soon as possible.
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device.
The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP
Cisco
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0171 Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
CVE-2018-0171: Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
Update August 20, 2025: Cisco is aware of continued exploitation activity of the vulnerability that is described in this advisory and strongly recommends that customers assess their systems and upgrade to a fixed software release as soon as possible. A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected d
Suricata
ET EXPLOIT Possible CVE-2018-0171 Exploit (PoC based)
suricata·2018-04-06·CVSS 9.8
CVE-2018-0171 [CRITICAL] ET EXPLOIT Possible CVE-2018-0171 Exploit (PoC based)
ET EXPLOIT Possible CVE-2018-0171 Exploit (PoC based)
Rule: alert tcp any any -> $HOME_NET 4786 (msg:"ET EXPLOIT Possible CVE-2018-0171 Exploit (PoC based)"; flow:established,to_server; content:"|00 00 00 01 00 00 00 01 00 00 00 07|"; depth:12; content:"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA"; distance:12; within:36; content:"BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB"; distance:4; within:44; reference:cve,2018-0171; reference:url,embedi.com/blog/cisco-smart-install-remote-code-execution/; classtype:attempted-admin; sid:2025472; rev:1; metadata:affected_product Cisco_ASA, attack_target Networking_Equipment, created_at 2018_04_06, cve CVE_2018_0171, deployment Perimeter, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 201
Exploit-DB
Cisco Smart Install - Crash (PoC)
exploitdb·2018-03-29
CVE-2018-0171 Cisco Smart Install - Crash (PoC)
Cisco Smart Install - Crash (PoC)
---
# smi_ibc_init_discovery_BoF.py
import socket
import struct
from optparse import OptionParser
# Parse the target options
parser = OptionParser()
parser.add_option("-t", "--target", dest="target", help="Smart Install Client", default="192.168.1.1") parser.add_option("-p", "--port", dest="port", type="int", help="Port of Client", default=4786) (options, args) = parser.parse_args()
def craft_tlv(t, v, t_fmt='!I', l_fmt='!I'):
return struct.pack(t_fmt, t) + struct.pack(l_fmt, len(v)) + v
def send_packet(sock, packet):
sock.send(packet)
def receive(sock):
return sock.recv()
if __name__ == "__main__":
print "[*] Connecting to Smart Install Client ", options.target, "port", options.port
con = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
con.con
Nuclei
Cisco Smart Install - Configuration Download
nuclei·CVSS 9.8
CVE-2018-0171 [CRITICAL] Cisco Smart Install - Configuration Download
Cisco Smart Install - Configuration Download
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data.
Template:
id: CVE-2018-0171
info:
name: Cisco Smart Install - Configuration Download
author: ritikchaddha,matejsmycka
severity: critical
description: |
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute a
Hackernews
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
blogs_hackernews·2026-07-14
CVE-2018-0171 U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors' and other cybercriminals' malicious activities, including ransomware attacks against Americans.
The VPN, named First VPN Service ( 1VPNS ), has been accused of offering its tools to ransomware groups, along with its 45-year-old Ukrainian administrator, Dmytro Rashevskyi. The department has also sanctioned Yegeniy Vladimirovich Silayev, a Belarusian national, for selling cryptors to he
Tenable
Cybersecurity Snapshot: Expert Advice for Securing Critical Infrastructure’s OT and Industrial Control Systems, IoT Devices and Network Infrastructure
blogs_tenable·2025-09-05
Cybersecurity Snapshot: Expert Advice for Securing Critical Infrastructure’s OT and Industrial Control Systems, IoT Devices and Network Infrastructure
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
US offers $10 million bounty for info on Russian FSB hackers
blogs_bleepingcomputer·2025-09-03·CVSS 9.8
[CRITICAL] US offers $10 million bounty for info on Russian FSB hackers
## US offers $10 million bounty for info on Russian FSB hackers
## Sergiu Gatlan
The U.S. Department of State is offering a reward of up to $10 million for information on three Russian Federal Security Service (FSB) officers involved in cyberattacks targeting U.S. critical infrastructure organizations on behalf of the Russian government.
The three individuals, Marat Valeryevich Tyukov, Mikhail Mikhailovich Gavrilov, and Pavel Aleksandrovich Akulov, are part of the FSB's Center 16 or Military Unit 71330, which is tracked as Berserk Bear, Blue Kraken, Crouching Yeti, Dragonfly, and Koala Team.
In March 2022, the three FBS officers were also charged for their involvement in a campaign that took place between 2012 and 2017, targeting U.S. government agencies, including the Nuclear Regulato
Tenable
Chinese State-Sponsored Actors Compromising Global Networks
blogs_tenable·2025-08-29
Chinese State-Sponsored Actors Compromising Global Networks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cybersecurity Snapshot: Agentic AI Security in Focus With Anthropic’s Chilling Abuse Disclosure and CSA’s New Identity Protection Framework
blogs_tenable·2025-08-29
Cybersecurity Snapshot: Agentic AI Security in Focus With Anthropic’s Chilling Abuse Disclosure and CSA’s New Identity Protection Framework
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Global Salt Typhoon hacking campaigns linked to Chinese tech firms
blogs_bleepingcomputer·2025-08-27·CVSS 9.8
[CRITICAL] Global Salt Typhoon hacking campaigns linked to Chinese tech firms
## Global Salt Typhoon hacking campaigns linked to Chinese tech firms
## Lawrence Abrams
The U.S. National Security Agency (NSA), the UK's National Cyber Security Centre (NCSC), and partners from over a dozen countries have linked the Salt Typhoon global hacking campaigns to three China-based technology firms.
According to the joint advisories [ NSA , NCSC ], Sichuan Juxinhe Network Technology Co. Ltd., Beijing Huanyu Tianqiong Information Technology Co., and Sichuan Zhixin Ruijie Network Technology Co. Ltd. have provided cyber products and services to China's Ministry of State Security and the People's Liberation Army, enabling cyber espionage operations tracked as Salt Typhoon.
Since at least 2021, the Chinese threat actors have breached government, telecommunications, transportation
Checkpoint
25th August – Threat Intelligence Report
blogs_checkpoint·2025-08-25
CVE-2025-43300 25th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 25th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 25th August, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
US pharmaceutical company Inotiv has experienced a ransomware attack that resulted in the unauthorized access and encryption of certain systems and data. The Qilin ransomware gang claimed responsibility and alleged the theft of approximately 162,000 files totaling 176GB.
Check Point Threat Emulation and Harmony Endpoint pr
Tenable
Cybersecurity Snapshot: Industrial Systems in Crosshairs of Russian Hackers, FBI Warns, as MITRE Updates List of Top Hardware Weaknesses
blogs_tenable·2025-08-22
Cybersecurity Snapshot: Industrial Systems in Crosshairs of Russian Hackers, FBI Warns, as MITRE Updates List of Top Hardware Weaknesses
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
FBI warns of Russian hackers exploiting 7-year-old Cisco flaw
blogs_bleepingcomputer·2025-08-21·CVSS 9.8
[CRITICAL] FBI warns of Russian hackers exploiting 7-year-old Cisco flaw
## FBI warns of Russian hackers exploiting 7-year-old Cisco flaw
## Sergiu Gatlan
The Federal Bureau of Investigation (FBI) has warned that hackers linked to Russia's Federal Security Service (FSB) are targeting critical infrastructure organizations in attacks exploiting a 7-year-old vulnerability in Cisco devices.
The FBI's public service announcement states that the state-backed hacking group, linked to the FSB's Center 16 unit and tracked as Berserk Bear (also known as Blue Kraken, Crouching Yeti, Dragonfly, and Koala Team), has been targeting Cisco networking devices using CVE-2018-0171 exploits to breach organizations worldwide.
Successful exploitation of CVE-2018-0171, a critical vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE software, can allow unauthen
Talos
Cherry pie, Douglas firs and the last trip of the summer
blogs_talos·2025-08-21
Cherry pie, Douglas firs and the last trip of the summer
(Welcome to this week’s edition of the Threat Source newsletter.)
Diane,
2:01 p.m., August 21st. I’ve just returned from a remarkable journey through Seattle and the misty roads of the Olympic Peninsula. If you ever find yourself driving beneath those towering Douglas firs or dragged by your partner through the Twilight Museum in Forks, I recommend stopping for a cup of hot, black coffee and a slice of cherry pie at any roadside diner. It’s nothing short of extraordinary.
But as I navigated the Rialto Beach tidepools (at 5:30 a.m., no less) and moss-laden trees of the Hoh Rainforest, I made a classic misstep: I forgot to connect to Wi-Fi the entire trip. By the time I returned, my high-speed data allowance had vanished into the mist, leaving me puzzled and restarting my cell phone for d
Talos
Cherry pie, Douglas firs and the last trip of the summer
blogs_talos·2025-08-21
Cherry pie, Douglas firs and the last trip of the summer
## Cherry pie, Douglas firs and the last trip of the summer
(Welcome to this week’s edition of the Threat Source newsletter.)
Diane,
2:01 p.m., August 21st. I’ve just returned from a remarkable journey through Seattle and the misty roads of the Olympic Peninsula. If you ever find yourself driving beneath those towering Douglas firs or dragged by your partner through the Twilight Museum in Forks, I recommend stopping for a cup of hot, black coffee and a slice of cherry pie at any roadside diner. It’s nothing short of extraordinary.
But as I navigated the Rialto Beach tidepools (at 5:30 a.m., no less) and moss-laden trees of the Hoh Rainforest, I made a classic misstep: I forgot to connect to Wi-Fi the entire trip. By the time I returned, my high-speed data allowance had vanished into th
Talos
Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices
blogs_talos·2025-08-20·CVSS 9.8
CVE-2018-0171 [CRITICAL] Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices
- Static Tundra is a Russian state-sponsored cyber espionage group linked to the FSB's Center 16 unit that has been operating for over a decade, specializing in compromising network devices for long-term intelligence gathering operations.
- The group actively exploits a seven-year-old vulnerability (CVE-2018-0171), which was patched at the time of the vulnerability publications, in Cisco IOS software's Smart Install feature, targeting unpatched and end-of-life network devices to steal configuration data and establish persistent access.
- Primary targets include organizations in telecommunications, higher education and manufacturing sectors across North America, Asia, Africa and Europe, with victims selected based on their strategic interest to the Russian government.
- Static Tundra employ
Talos
Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices
blogs_talos·2025-08-20·CVSS 9.8
CVE-2018-0171 [CRITICAL] Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices
## Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices
Static Tundra is a Russian state-sponsored cyber espionage group linked to the FSB's Center 16 unit that has been operating for over a decade, specializing in compromising network devices for long-term intelligence gathering operations.
The group actively exploits a seven-year-old vulnerability (CVE-2018-0171), which was patched at the time of the vulnerability publications, in Cisco IOS software's Smart Install feature, targeting unpatched and end-of-life network devices to steal configuration data and establish persistent access.
Primary targets include organizations in telecommunications, higher education and manufacturing sectors across North America, Asia, Africa and Europe, w
Bleepingcomputer
Chinese hackers breached National Guard to steal network configurations
blogs_bleepingcomputer·2025-07-17
Chinese hackers breached National Guard to steal network configurations
## Chinese hackers breached National Guard to steal network configurations
## Lawrence Abrams
The Chinese state-sponsored hacking group known as Salt Typhoon breached and remained undetected in a U.S. Army National Guard network for nine months in 2024, stealing network configuration files and administrator credentials that could be used to compromise other government networks.
Salt Typhoon is a Chinese state-sponsored hacking group that is believed to be affiliated with China's Ministry of State Security (MSS) intelligence agency. The hacking group has gained notoriety over the past two years for its wave of attacks on telecommunications and broadband providers worldwide, including AT&T, Verizon, Lumen , Charter, Windstream , and Viasat .
The goal of some of these attacks was to gain
Greynoiseio
GreyNoise Observes Active Exploitation of Cisco Vulnerabilities Tied to Salt Typhoon Attacks
blogs_greynoiseio·2025-02-24·CVSS 9.8
[CRITICAL] GreyNoise Observes Active Exploitation of Cisco Vulnerabilities Tied to Salt Typhoon Attacks
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Talos
Weathering the storm: In the midst of a Typhoon
blogs_talos·2025-02-20·CVSS 9.8
[CRITICAL] Weathering the storm: In the midst of a Typhoon
## Weathering the storm: In the midst of a Typhoon
## Summary
Cisco Talos has been closely monitoring reports of widespread intrusion activity against several major U.S. telecommunications companies. The activity, initially reported in late 2024 and later confirmed by the U.S. government, is being carried out by a highly sophisticated threat actor dubbed Salt Typhoon. This blog highlights our observations on this campaign and identifies recommendations for detection and prevention of the actor’s activities.
Public reporting has indicated that the threat actor was able to gain access to core networking infrastructure in several instances and then use that infrastructure to collect a variety of information. There was only one case in which we found evidence suggesting that a Cisco vulnera
Talos
Weathering the storm: In the midst of a Typhoon
blogs_talos·2025-02-20·CVSS 9.8
[CRITICAL] Weathering the storm: In the midst of a Typhoon
## Summary
Cisco Talos has been closely monitoring reports of widespread intrusion activity against several major U.S. telecommunications companies. The activity, initially reported in late 2024 and later confirmed by the U.S. government, is being carried out by a highly sophisticated threat actor dubbed Salt Typhoon. This blog highlights our observations on this campaign and identifies recommendations for detection and prevention of the actor’s activities.
Public reporting has indicated that the threat actor was able to gain access to core networking infrastructure in several instances and then use that infrastructure to collect a variety of information. There was only one case in which we found evidence suggesting that a Cisco vulnerability (CVE-2018-0171) was likely abused. In all the
Bleepingcomputer
Chinese hackers use custom malware to spy on US telecom networks
blogs_bleepingcomputer·2025-02-20·CVSS 9.8
[CRITICAL] Chinese hackers use custom malware to spy on US telecom networks
## Chinese hackers use custom malware to spy on US telecom networks
## Bill Toulas
The Chinese state-sponsored Salt Typhoon hacking group uses a custom utility called JumbledPath to stealthily monitor network traffic and potentially capture sensitive data in cyberattacks on U.S. telecommunication providers.
Salt Typhoon (aka Earth Estries, GhostEmperor, and UNC2286) is a sophisticated hacking group active since at least 2019, primarily focusing on breaching government entities and telecommunications companies.
Recently, the U.S. authorities have confirmed that Salt Typhoon was behind several successful breaches of telecommunication service providers in the U.S., including Verizon, AT&T, and Lumen Technologies.
It was later revealed that Salt Typhoon managed to tap into the private com
Tenable
Cisco Smart Install - How to Prevent Attacks on Switches
blogs_tenable·2018-04-11
Cisco Smart Install - How to Prevent Attacks on Switches
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cisco Smart Install - How to Prevent Attacks on Switches
blogs_tenable·2018-04-11·CVSS 9.8
CVE-2018-0171 [CRITICAL] Cisco Smart Install - How to Prevent Attacks on Switches
Blog / Research
Subscribe
# Cisco Smart Install - How to Prevent Attacks on Switches
Steve Tilson
April 11, 2018
2 Min Read
There’s been a flurry of activity around the Cisco Smart Install feature recently. Last week, we posted a tech blog about CVE-2018-0171, a critical vulnerability in Cisco’s Smart Install feature that called for immediate mitigation as proof-of-concept code was released publicly. Now, a wave of attacks has moved through data centers across the internet targeting Cisco switches with Smart Install in various countries across the globe. This time around, attackers are (mis)using the Smart Install protocol with mal intent on Cisco’s switches that are open with Smart Install support. Once the attacker gains access, they rewrite the Cisco IOS image on the switches and c
Tenable
Proof of Concept (and Patch) for Critical Cisco IOS Vulnerability: CVE-2018-0171
blogs_tenable·2018-04-03·CVSS 9.8
[CRITICAL] Proof of Concept (and Patch) for Critical Cisco IOS Vulnerability: CVE-2018-0171
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Proof of Concept (and Patch) for Critical Cisco IOS Vulnerability: CVE-2018-0171
blogs_tenable·2018-04-03·CVSS 9.8
CVE-2018-0171 [CRITICAL] Proof of Concept (and Patch) for Critical Cisco IOS Vulnerability: CVE-2018-0171
Blog / Cyber Exposure Alerts
Subscribe
# Proof of Concept (and Patch) for Critical Cisco IOS Vulnerability: CVE-2018-0171
Steve Tilson
April 3, 2018
2 Min Read
Embedi, a security firm, has discovered a major security flaw in the Cisco Smart Install code. According to Embedi and Cisco, “A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device.”
Smart Install is Cisco’s quick configuration method for their switches. Cisco states that in a Smart Install network, you can use the Zero-Touch Installation process to install new access layer switches to the network wi
Greynoiseio
Storm Watch
blogs_greynoiseio
Storm Watch
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Threat Intel
Salt Typhoon (Salt Typhoon)
threat_intel·CVSS 9.8
[CRITICAL] Salt Typhoon (Salt Typhoon)
# Threat Actor Profile: Salt Typhoon
ATT&CK ID: G1045
Also known as: Salt Typhoon
Suspected origin: China
## Overview
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecommunication and internet service providers (ISP).(Citation: US Dept. of Treasury Salt Typhoon JAN 2025)(Citation: Cisco Salt Typhoon FEB 2025)
## Techniques (TTPs)
### Reconnaissance
- T1590.004 Network Topology
Usage: Salt Typhoon has used configuration files from exploited network devices to help discover upstream and downstream network segments.(Citation: Cisco Salt Typhoon FEB 2025)
### Resource Development
- T1587.001 Malware
Usage: Salt Typhoon has used custom tooling
arXiv
CTI Dataset Construction from Telegram
arxiv_fulltext·2025-09-25
CTI Dataset Construction from Telegram
September 2025
## Abstract
Cyber Threat Intelligence (CTI) enables organizations to anticipate, detect, and mitigate evolving cyber threats. Its effectiveness depends on high-quality datasets, which support model development, training, evaluation, and benchmarking. Building such datasets is crucial, as attack vectors and adversary tactics continually evolve. Recently, Telegram has gained prominence as a valuable CTI source, offering timely and diverse threat-related information that can help address these challenges. In this work, we address these challenges by presenting an end-to-end automated pipeline that systematically collects and filters threat-related content from Telegram. The pipeline identifies relevant Telegram channels and scrapes 145,349 messages from 12 curated channels ou
http://www.securityfocus.com/bid/103538http://www.securitytracker.com/id/1040580https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490http://www.securityfocus.com/bid/103538http://www.securitytracker.com/id/1040580https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0171
2018-03-28
Published
2021-11-03
Added to CISA KEV
Exploited in the wild