Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection. Vulnerabilities may exist in software that can be used to disable or circumvent security features. Adversaries may have prior knowledge through [Remote System Information Discovery](https://attack.mitre.org/techniques/T0888) about security features implemented on control devices. These device security features will likely be targeted directly for exploitation. There are examples of firmware RAM/ROM consistency checks on control devices being targeted by adversaries to enable the installation of malicious [System Firmware](https://attack.mitre.org/techniques/T0857).

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Workstation
is related to Intelligent Electronic Device (IED)
is related to Firewall
is related to Programmable Automation Controller (PAC)
is related to Jump Host
is related to Data Gateway
is related to Distributed Control System (DCS) Controller
is related to Data Historian
is related to Routers
is related to Safety Controller
is related to Control Server
is related to Virtual Private Network (VPN) Server
is related to Switch
is related to Programmable Logic Controller (PLC)
is related to Human-Machine Interface (HMI)
is related to Application Server
is blocked by Threat Intelligence Program
is blocked by Exploit Protection
is blocked by Application Isolation and Sandboxing
is blocked by Update Software
is blocked by Detection of Exploitation for Evasion
Impressum Deutsch Englisch