As cited
Citation snapshot as of .
vulnerabilities
GreyNoise Observes Active Exploitation of Cisco Vulnerabilities Tied to Salt Typhoon Attacks
GreyNoise detected active exploitation attempts against two Cisco vulnerabilities, CVE-2023-20198 and CVE-2018-0171, with over 110 malicious IP addresses targeting the former vulnerability from multiple countries. The vulnerabilities were mentioned in recent Salt Typhoon reporting but GreyNoise has not attributed the observed exploitation to the Chinese state-sponsored group.
Why it matters: Organizations running affected Cisco infrastructure should immediately verify if these vulnerabilities are patched, as multiple threat actors are actively exploiting them in the wild.
- Source published
- First seen by Cybersecurity Tracker