Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate device behavior that is difficult to detect. (Citation: Cisco Synful Knock Evolution)(Citation: Cisco Blog Legacy Device Attacks) ROMMON is a Cisco network device firmware that functions as a boot loader, boot image, or boot helper to initialize hardware and software when the platform is powered on or reset. Similar to [TFTP Boot](https://attack.mitre.org/techniques/T1542/005), an adversary may upgrade the ROMMON image locally or remotely (for example, through TFTP) with adversary code and restart the device in order to overwrite the existing ROMMON image. This provides adversaries with the means to update the ROMMON to gain persistence on a system in a way that may be difficult to detect.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Boot Integrity
is blocked by Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit
is blocked by Audit
is blocked by Network Intrusion Prevention
is blocked by Asset Inventories
is blocked by Configuration Change Control
is blocked by Access Restriction For Change
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Cryptographic Module Authentication
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Boundary Protection
is blocked by Non-Modifiable Executable Programs
is blocked by Criticality Analysis During Development
is blocked by Security, Compliance & Resilience Testing Throughout Development
is blocked by Developer Configuration Management
is blocked by Software & Firmware Patching
is blocked by Vulnerability Scanning
Impressum German English