Adversaries may leverage manufacturer or supplier set default credentials on control system devices. These default credentials may have administrative permissions and may be necessary for initial configuration of the device. It is general best practice to change the passwords for these accounts as soon as possible, but some manufacturers may have devices that have passwords or usernames that cannot be changed.(Citation: Keith Stouffer May 2015) Default credentials are normally documented in an instruction manual that is either packaged with the device, published online through official means, or published online through unofficial means. Adversaries may leverage default credentials that have not been properly modified or disabled.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Distributed Control System (DCS) Controller
is related to Intelligent Electronic Device (IED)
is related to Jump Host
is related to Application Server
is related to Field I/O
is related to Switch
is related to Remote Terminal Unit (RTU)
is related to Virtual Private Network (VPN) Server
is related to Control Server
is related to Safety Controller
is related to Firewall
is related to Data Historian
is related to Human-Machine Interface (HMI)
is related to Data Gateway
is related to Programmable Logic Controller (PLC)
is related to Routers
is related to Workstation
is related to Programmable Automation Controller (PAC)
is blocked by Detection of Default Credentials
is blocked by Password Policies
is blocked by Access Management
Impressum Deutsch Englisch