Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot (netbooting) is commonly used by network administrators to load configuration-controlled network device images from a centralized management server. Netbooting is one option in the boot sequence and can be used to centralize, manage, and control device images. Adversaries may manipulate the configuration on the network device specifying use of a malicious TFTP server, which may be used in conjunction with [Modify System Image](https://attack.mitre.org/techniques/T1601) to load a modified image on device startup or reset. The unauthorized image allows adversaries to modify device configuration, add malicious capabilities to the device, and introduce backdoors to maintain control of the network device while minimizing detection through use of a standard functionality. This technique is similar to [ROMMONkit](https://attack.mitre.org/techniques/T1542/004) and may result in the network device running a modified image. (Citation: Cisco Blog Legacy Device Attacks)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Network Intrusion Prevention
is blocked by Operating System Configuration
is blocked by Privileged Account Management
is blocked by Limit Access to Resource Over Network
is blocked by Detection Strategy for T1542.005 Pre-OS Boot: TFTP Boot
is blocked by Audit
is blocked by Boot Integrity
is blocked by Asset Inventories
is blocked by Configuration Change Control
is blocked by Access Restriction For Change
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Identification & Authentication for Non-Organizational Users
is blocked by Cryptographic Module Authentication
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Boundary Protection
is blocked by Non-Modifiable Executable Programs
is blocked by Criticality Analysis During Development
is blocked by Security, Compliance & Resilience Testing Throughout Development
is blocked by Developer Configuration Management
is blocked by Software & Firmware Patching
is blocked by Vulnerability Scanning
Impressum Deutsch Englisch