Network Infraxploit [Guest Diary], (Wed, Apr 9th)
ID: 66053fb7-8d26-5a66-b89d-17402430dd1f
STIX ID: report--66053fb7-8d26-5a66-b89d-17402430dd1f
Feed Name: SANS ISC Diary
Threat Score
This report analyzes CVE-2018-0171 (Cisco Smart Install remote code execution), demonstrating use of the SIET exploit to retrieve a device's running configuration via TFTP (with packet-level evidence), explains attacker capabilities (config exfiltration, IOS replacement), notes the prevalence of exposed Smart Install services, and cites observed active exploitation by the APT 'Salt Typhoon' in large telecom attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
