CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

GreyNoise Observes Active Exploitation of Cisco Vulnerabilities Tied to Salt Typhoon Attacks

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 1919

As cited

Citation snapshot as of .

vulnerabilities

GreyNoise Observes Active Exploitation of Cisco Vulnerabilities Tied to Salt Typhoon Attacks

GreyNoise detected active exploitation attempts against two Cisco vulnerabilities, CVE-2023-20198 and CVE-2018-0171, with over 110 malicious IP addresses targeting the former vulnerability from multiple countries. The vulnerabilities were mentioned in recent Salt Typhoon reporting but GreyNoise has not attributed the observed exploitation to the Chinese state-sponsored group.

Why it matters: Organizations running affected Cisco infrastructure should immediately verify if these vulnerabilities are patched, as multiple threat actors are actively exploiting them in the wild.

Source published
First seen by Cybersecurity Tracker

Source attribution