Security researchers have discovered hundreds of federal network devices with exposed management interfaces violating the recently mandated CISA security requirements detailed in the Binding Operational Directive (BOD) 23-02.
The Cybersecurity and Infrastructure Security Agency (CISA) directed all federal civilian executive branch agencies to implement the requirements within 14 days to secure internet-exposed devices and reduce the federal attack surface.
Censys researchers analyzed more than 50 federal agencies and discovered over 100 FCEB information systems and over 13,000 unique hosts, with some exposing interfaces included in CISA’s directive.
CISA’s security requirements demand restriction of management interfaces
The directive targeted dedicated device interfaces (networked management interfaces) accessible over network protocols and intended for authorized users to manage the network itself or a group of devices.
It covered named physical devices such as routers, switches, firewalls, VPN concentrators, proxies, load balancers, and out of band server management interfaces (such as iLo and iDRAC).
Similarly, devices using FTP, SNMP, Telnet, TFTP, RDP, rlogin, Remote Shell, Secure Shell (SSH), SMB, VNC, and X Window System management interfaces were affected.
Although it included devices using Hypertext Transfer Protocol (HTTP) and Hypertext Transfer Protocol Secure (HTTP) management interfaces, it excluded web applications and interfaces for managing Cloud Service Provider (CSP) offerings, including Application Programming Interfaces (APIs) or management portals.
Additionally, federal agencies must ensure that the management interfaces of all existing and newly added devices are inaccessible over the public internet and only in internal enterprise networks. The dedicated management interfaces must also enforce access control through a policy enforcement point separate from the interface itself as part of a Zero Trust Architecture.
CISA Director Jen Easterly said the directive intends to reduce the attack surface exploited by threat actors to gain unrestricted access to organizational networks. While CISA mandates all FCEB agencies to meet the security requirements, Easterly encouraged other organizations across all sectors to follow suit.
“While this Directive only applies to federal civilian agencies, as the threat extends to every sector, we urge all organizations to adopt this guidance,” she said. “When it comes to reducing cyber risk and ensuring resilience, we all have a role to play.”
Praising CISA’s security requirements, Tom Kellermann, SVP of Cyber Strategy at Contrast Security, said the directive was direly needed.
“The CISA Binding Directive cannot come soon enough,” Kellermann said. “Federal Agencies must comply immediately and conduct threat hunting to ascertain if intrusions have already occurred,” said Kellermann.
Numerous federal network devices violate CISA security requirements
Censys researchers discovered thousands of hosts exposing networked management interfaces violating CISA security requirements.
“Throughout our investigation, we discovered a total of over 13,000 distinct hosts spread across more than 100 autonomous systems associated with these entities,” the researchers said. “Examining the services running on these hosts, Censys found hundreds of publicly exposed devices within the scope outlined in the directive.”
They discovered approximately 250 web interfaces exposing appliances running remote protocols covered by CISA’s directive, such as SSH and TELNET. These included Cisco network devices exposing Adaptive Security Device Manager interfaces, Cradlepoint router interfaces, Fortinet Fortiguard, and SonicWall appliances. Similarly, they discovered 15 exposed interfaces with FTP, SMB, NetBIOS, and SNMP remote access protocols.
The researchers warned that some of the federal network devices exposed interfaces with a long history of exploitation, elevating the risk of cyber attacks.
“These protocols have a history of security vulnerabilities, and exposing them to the internet raises the risk of being targeted by threat actors trying to gain remote unauthorized access to government infrastructure.”
Tomer Bar, VP of Security Research at SafeBreach, drew attention to the large number of federal network devices violating CISA’s security requirements.
“Unlike spear-phishing and other client-side attacks, this attack vector does not require any action on the part of the victim, making it much easier to achieve and exploit. It reminds us of the importance of self-checks like scanning and actively enumerating your own network,” noted Bar.
Bar warned that threat actors could exploit exposed federal network devices for DDoS attacks, crypto-mining, supply chain attacks, and waterhole attacks.
Federal network devices are exposed beyond CISA’s security requirements
Censys researchers also discovered other federal network devices with exposed interfaces beyond the scope of CISA’s security requirements. They included multiple hosts with exposed instances of MOVEit, GoAnywhere MFT, SolarWinds Serv-U, and VanDyke VShell file transfer systems.
Censys also discovered ten HTTP instances exposing file systems’ directory listings, risking sensitive information exposure via data files (backups, SQL files, .csv, excel worksheets), configuration files (.ini config files, config.js, wp-config.php), shell scripts, and SSH keys, among others.
Similarly, the researchers discovered exposed Barracuda Email Security Gateway appliances, which were exploited by Chinese state-sponsored threat actors, since October 2022, according to cybersecurity firm Mandiant.
Others include 150 end-of-life (EOL) software instances, including Microsoft Internet Information Services (IIS), OpenSSL, and Exim. Outdated software rarely receives security updates and might have zero-days or unpatched exploited vulnerabilities.
“With little oversight and concern about potential threats, devices can get added to the network under the guise of “supporting the mission” or being “mission critical,” which absolves them from all scrutiny,” said James Cochran, Director of Endpoint Security at Tanium. “Proper mitigations are not put in place, and the devices tend to be forgotten about by [the] leadership.”

