Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets.(Citation: NVD CVE-2016-6662)(Citation: CIS Multiple SMB Vulnerabilities)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)(Citation: Cisco Blog Legacy Device Attacks)(Citation: NVD CVE-2014-7169) On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.(Citation: Recorded Future ESXiArgs Ransomware 2023)(Citation: Ars Technica VMWare Code Execution Vulnerability 2021) Depending on the flaw being exploited, this may also involve [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203). If an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the [Cloud Instance Metadata API](https://attack.mitre.org/techniques/T1552/005)), exploit container host access via [Escape to Host](https://attack.mitre.org/techniques/T1611), or take advantage of weak identity and access management policies. Adversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses.(Citation: Mandiant Fortinet Zero Day)(Citation: Wired Russia Cyberwar) For websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.(Citation: OWASP Top 10)(Citation: CWE top 25)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Application Isolation and Sandboxing
is blocked by Filter Network Traffic
is blocked by Network Segmentation
is blocked by Vulnerability Scanning
is blocked by Privileged Account Management
is blocked by Exploit Protection
is blocked by Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress)
is blocked by Limit Access to Resource Over Network
is blocked by Update Software
is blocked by Asset Inventories
is blocked by Access Restriction For Change
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Mobile Code
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Identification & Authentication for Non-Organizational Users
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Assessments
is blocked by Cross Domain Solution (CDS)
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Secure Engineering Principles
is blocked by Application Partitioning
is blocked by Process Isolation
is blocked by Security Function Isolation
is blocked by Heterogeneity
is blocked by Concealment & Misdirection
is blocked by Input Data Validation
is blocked by Threat Hunting
is blocked by Software & Firmware Patching
is blocked by Vulnerability Scanning
Impressum German English