Adversaries may target insecure credentials as a means to persist on a system or device or move laterally from one system or device to another. Insecure credentials may appear as default credentials which are pre-configured credentials on a system, device, or software that are well-known in documentation or hard-coded credentials which are built into the system, device, or software that cannot be changed or not easily changed because of the impact on control processes.(Citation: NIST SP 800-82r3)(Citation: ICS-ALERT-13-164-01)(Citation: OT IceFall) Adversaries often times use insecure credentials to evade detection as they are typically forgotten about by system and device owners.

Subissues

Issuelinks
Summary Description
Default Credentials Adversaries may leverage manufacturer or supplier set default credentials on control system devices. These default credentials may have administrative permissions and may be necessary for initial configuration of the device. It is general best practice to change the passwords for these accounts as soon as possible, but some manufacturers may have devices that have passwords or usernames that cannot be changed.(Citation: Keith Stouffer May 2015) Default credentials are normally documented in an instruction manual that is either packaged with the device, published online through official means, or published online through unofficial means. Adversaries may leverage default credentials that have not been properly modified or disabled.
Hardcoded Credentials Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset. Examples credentials that may be hardcoded in an asset include: * Username/Passwords * Cryptographic keys/Certificates * API tokens Unlike [Default Credentials](https://attack.mitre.org/techniques/T0812), these credentials are built into the system in a way that they either cannot be changed by the asset owner, or may be infeasible to change because of the impact it would cause to the control system operation. These credentials may be reused across whole product lines or device models and are often not published or known to the owner and operators of the asset.(Citation: ICS-ALERT-13-164-01)(Citation: OT IceFall) Adversaries may utilize these hardcoded credentials to move throughout the control system environment or provide reliable access for their tools to interact with industrial assets.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Distributed Control System (DCS) Controller
is related to Routers
is related to Programmable Logic Controller (PLC)
is related to Safety Controller
is related to Human-Machine Interface (HMI)
is related to Intelligent Electronic Device (IED)
is related to Data Gateway
is related to Control Server
is related to Remote Terminal Unit (RTU)
is related to Programmable Automation Controller (PAC)
is related to Jump Host
is related to Firewall
is related to Application Server
is related to Field I/O
is related to Data Historian
is related to Workstation
is related to Switch
is related to Virtual Private Network (VPN) Server
is part of Lateral Movement
is blocked by Detection of Insecure Credentials
is blocked by Access Management
Impressum German English