Joint advisory on Russian activity against poorly secured routers
A consortium of 19 agencies from 13 countries has published an advisory on Russian activity targeting poorly configured edge devices. The advisory focuses primarily on the risk of exposing SNMPv1 and SNMPv2 on routers. These are insecure legacy protocols, easily exploited when exposed, particularly where access is protected only by default community strings, meaning factory-set SNMP passwords. The advisory also highlights specific CVEs that have been targeted. Recommendations include migrating to SNMPv3 and patching devices.
What this means for your organisation
SNMP is the kind of configuration set once, long ago, and never revisited. It is rarely anyone's job. The consequence is real nonetheless: exposed SNMP hands an attacker the map of your network and, at worst, the ability to change its configuration. When 19 agencies jointly point at something this basic, it is because the evidence says the problem is widespread.
Berigo recommends
- Map which routers and network devices have SNMP enabled and which versions are in use.
- Disable SNMPv1 and SNMPv2 where they are not strictly required, and move to SNMPv3 with authentication and encryption.
- Replace all default community strings and block SNMP from the internet.
- Bring network equipment into the routine patching plan, with a named owner for each device type.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch