Adversaries may activate firmware update mode on devices to prevent expected response functions from engaging in reaction to an emergency or process malfunction. For example, devices such as protection relays may have an operation mode designed for firmware installation. This mode may halt process monitoring and related functions to allow new firmware to be loaded. A device left in update mode may be placed in an inactive holding state if no firmware is provided to it. By entering and leaving a device in this mode, the adversary may deny its usual functionalities.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Human-Machine Interface (HMI)
is related to Data Gateway
is related to Programmable Automation Controller (PAC)
is related to Distributed Control System (DCS) Controller
is related to Safety Controller
is related to Remote Terminal Unit (RTU)
is related to Intelligent Electronic Device (IED)
is related to Field I/O
is related to Programmable Logic Controller (PLC)
is blocked by Network Allowlists
is blocked by Human User Authentication
is blocked by Software Process and Device Authentication
is blocked by Communication Authenticity
is blocked by Access Management
is blocked by Detection of Activate Firmware Update Mode
is blocked by Filter Network Traffic
is blocked by Network Segmentation
is blocked by Authorization Enforcement
Impressum Deutsch Englisch