Adversaries may leverage weaknesses to exploit internet-facing software for initial access into an industrial network. Internet-facing software may be user applications, underlying networking implementations, an assets operating system, weak defenses, etc. Targets of this technique may be intentionally exposed for the purpose of remote management and visibility. An adversary may seek to target public-facing applications as they may provide direct access into an ICS environment or the ability to move into the ICS network. Publicly exposed applications may be found through online tools that scan the internet for open ports and services. Version numbers for the exposed application may provide adversaries an ability to target specific known vulnerabilities. Exposed control protocol or remote access ports found in Commonly Used Port may be of interest by adversaries.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Application Server
is related to Virtual Private Network (VPN) Server
is related to Workstation
is related to Firewall
is blocked by Update Software
is blocked by Vulnerability Scanning
is blocked by Exploit Protection
is blocked by Privileged Account Management
is blocked by Application Isolation and Sandboxing
is blocked by Detection of Exploit Public-Facing Application
is blocked by Network Segmentation
Impressum German English