On 16 October 2023, a hacker identified a vulnerability in the GUI in a major network manufactures software, adding to the already long list of major network and firewall equipment vulnerabilities active at scale. Within a single day, the number of compromised devices of the entity reached approximately 40,000. A second zero-day exploit was discovered on October 20th, escalating the total count of affected devices to an alarming 60,000.
Incidents like these underscore the critical importance of designing devices with security in mind and are quickly becoming a focal point in discussions as well as being emphasised by the Australian Cyber Security Centre (ACSC).
How are standalone network devices exploited?
Manufacturers often ship devices with a default configuration aimed at balancing security and functionality. Typically, this configuration minimises exposure to security vulnerabilities by closing most ports by default, leaving only those essential for device management and crucial functions open.
However, these open ports often include those used for management interfaces like SSH, Telnet, or HTTP/HTTPS. The responsibility then falls on the customer to either harden these ports or enable secure management options that eliminate their exposure to the internet or other networks.
To enhance security further, these devices can connect to additional authentication systems such as RADIUS and TACACS, which customers may need to set up and manage, adding another layer of complexity.
Modern alternatives for device security
If you are concerned about the security of your corporate networks protected by these kinds of devices, there are modern alternatives that can either augment or replace them.
Cloud-native networking and security solutions operate on the internet and adopt an internet-centric approach to security. Many of these solutions offer features like 'call home securely,' device authentication, and integrated certificate authorities. Access to these devices is often restricted and managed through a centralised controller or cloud-based user interface that includes multiple layers of security measures such as Single Sign-On (SSO) and authorisation mechanisms.
Effectively, these systems can 'hide' your internet-exposed devices from prying eyes. These platforms are tailor-made for the cloud-native world we currently inhabit.
How do hackers find devices on the internet?
One of the first things hackers do is conduct internet reconnaissance, scouring the web for easy entry points such as devices with open ports, unsecured systems, and vulnerable servers. They use common tools and exploits to target and infiltrate these systems.
Many of these tools are publicly accessible services that are extremely useful for seeing the world from a hacker’s point of view. Shodan.io is a great tool for viewing exposed internet infrastructure, including your own, while FullHunt.io provides insights into the attack surface of web domains and applications. However, these tools are a double-edged sword; they are as useful to customers and organisations as they are to individuals with nefarious purposes.
A simple example
Running a Shodan search for "IOS XE," revealing the IOS XE devices currently visible on the internet. Some of these networks are Service Provider networks – either SP Internet Routers which have not been hardened/misconfigured or customer routers.
The below image is an example of the Shodan search: The data reveals that over 1,700 devices remain visible on the internet as of late October 2023.