The US Cybersecurity and Infrastructure Security Agency has issued a warning regarding active attacks that leverage a security flaw in Cisco network equipment originally identified in 2007. The agency has added the issue, designated as CVE-2007-4816, to its Known Exploited Vulnerabilities catalog to alert organizations to the immediate threat.
The vulnerability impacts Cisco IOS, the operating system utilized by the company for numerous routers and other networking hardware. It stems from how version 1 of the Internet Key Exchange protocol handles secure virtual private network connections. When this feature is active on an unpatched device, a remote attacker can transmit specially crafted data packets that cause the system to crash.
Depending on the specific configuration of the affected hardware, the resulting denial-of-service condition can take the device offline. In some instances, the flaw may also permit unauthorized code execution on the compromised system.
Cisco released security updates to address the issue in 2007, but the agency notes that many organizations continue to operate equipment that has reached the end of its service life or lacks proper maintenance.
CISA has directed US federal agencies to implement mitigation measures within a specified timeframe. The agency is also advising other organizations to inventory their network equipment to determine if they are still using affected devices. Those with vulnerable hardware are urged to install available updates or replace unsupported equipment.
The US agency has not disclosed the identity of the threat actors behind the campaign. Details regarding specific victims or the scope of the attacks remain unclear. The exploitation has not been attributed to any particular ransomware group or criminal organization.
