CRITICAL: Accessible Cisco Smart Install Report

DESCRIPTION LAST UPDATED: 2023-12-08

DEFAULT SEVERITY LEVEL: CRITICAL

This report identifies hosts that have the Cisco Smart Install feature running and are accessible to the Internet at large.

This feature can be used to read or potentially modify a switch’s configuration.

More details can be found on Cisco’s PSIRT blog.

You can track current Cisco Smart Install exposure on our Dashboard.

Severity levels are described here.

For more information on our scanning efforts, check out our >Internet scanning summary page.

Filename: scan_cisco_smart_install

Fields

  • timestamp
    Time that the IP was probed in UTC+0
  • severity
    Severity level
  • ip
    The IP address of the device in question
  • protocol
    Protocol that the response came on (always TCP)
  • port
    Port that the response came from (4786/TCP)
  • hostname
    Reverse DNS name of the device in question
  • tag
    Will always be cisco-smart-install
  • asn
    ASN of where the device in question resides
  • geo
    Country where the device in question resides
  • region
    State / Province / Administrative region where the device in question resides
  • city
    City in which the device in question resides
  • naics
    North American Industry Classification System Code
  • hostname_source
    Hostname source
  • Sector
    Sector the device belongs to

Sample

"timestamp","severity","ip","protocol","port","hostname","tag","asn","geo","region","city","naics","hostname_source","sector"
"2010-02-10 00:00:00",critical,192.168.0.1,tcp,4786,node01.example.com,cisco-smart-install,64512,ZZ,Region,City,0,,
"2010-02-10 00:00:01",critical,192.168.0.2,tcp,4786,node02.example.com,cisco-smart-install,64512,ZZ,Region,City,0,,
"2010-02-10 00:00:02",critical,192.168.0.3,tcp,4786,node03.example.com,cisco-smart-install,64512,ZZ,Region,City,0,,

Our 130 Report Types