The US Cyber and Infrastructure Security Agency (CISA) has issued a binding operational directive stating that internet-facing management interfaces cannot be adequately secured. As a result, CISA has instructed US government agencies to disable these interfaces.
The directive covers a wide range of devices, including routers, switches, firewalls, VPN concentrators, proxies, load balancers, and out-of-band server management interfaces such as iLo and iDRAC. CISA’s directive encompasses various protocols, including HTTP, HTTPS, FTP, SNMP, Telnet, TFTP, RDP, rlogin, RSH, SSH, SMB, VNC, and X11.
CISA highlights that web-based management interfaces have long been susceptible to security vulnerabilities. Numerous patches for management interfaces have been released by companies like Aruba Networks, Cisco Systems, and Starlink terminals in the past year alone. Even older protocols like SNMP, which dates back to the late 1980s, have been exploited, with incidents of Fancy Bear threat actors leveraging a 2017 bug in Cisco routers.
It is possible that Australian government agencies may receive a similar directive, given the close coordination between US and Australian cybersecurity organizations.


