
CVE-2018-0171, CVE-2008-4128: Cisco Smart Install — Grid Attack Attempt Thwarted (June 2024)
CVE-2018-0171, CVE-2008-4128 — Cisco Smart Install
CVE-2018-0171 and CVE-2008-4128 are critical vulnerabilities in Cisco Smart Install and legacy Cisco devices. Both allow unauthenticated remote code execution and device takeover; CVE-2018-0171 carries a CVSS score of 9.8. These flaws are under active exploitation by Russian state-sponsored actors, specifically the FSB-linked Berzerk Bear/Dragonfly group.
Attack Vector
Attackers scan for exposed Cisco Smart Install protocol (TCP/4786) and legacy device interfaces. Exploitation requires network access to vulnerable devices. Successful exploitation enables remote code execution, configuration manipulation, and potential destructive actions against infrastructure. In this incident, attackers attempted to disrupt Poland's energy grid, aiming to cause a power outage affecting 500,000 people. Authorities confirmed the attack leveraged these CVEs but was ultimately unsuccessful.
Who Is at Risk
All organizations running unpatched Cisco devices supporting Smart Install or affected by CVE-2018-0171 and CVE-2008-4128 are at risk. Confirmed targets include Poland's energy grid. Critical infrastructure operators, especially in North America and Europe, should prioritize patching. Devices with public-facing management interfaces or legacy configurations are most exposed.
Patch & Mitigate
- Patch: Upgrade to Cisco IOS software releases that address CVE-2018-0171 and CVE-2008-4128 immediately. Refer to Cisco advisories for specific fixed versions.
- Workaround: Disable Smart Install protocol if not required. Restrict management access to trusted networks only.
- Detect: Monitor for unusual connections to TCP/4786, unauthorized config changes, and device reboots. Review logs for Smart Install-related activity.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers exploit exposed Cisco management interfaces for entry.
- TA0007 — Discovery: Adversaries enumerate network devices and configurations after access.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

