System firmware on modern assets is often designed with an update feature. Older device firmware may be factory installed and require special reprograming equipment. When available, the firmware update feature enables vendors to remotely patch bugs and perform upgrades. Device firmware updates are often delegated to the user and may be done using a software update package. It may also be possible to perform this task over the network. An adversary may exploit the firmware update feature on accessible devices to upload malicious or out-of-date firmware. Malicious modification of device firmware may provide an adversary with root access to a device, given firmware is one of the lowest programming abstraction layers.(Citation: Basnight, Zachry, et al.)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Distributed Control System (DCS) Controller
is related to Virtual Private Network (VPN) Server
is related to Data Gateway
is related to Firewall
is related to Programmable Logic Controller (PLC)
is related to Safety Controller
is related to Remote Terminal Unit (RTU)
is related to Intelligent Electronic Device (IED)
is related to Human-Machine Interface (HMI)
is related to Switch
is blocked by Human User Authentication
is blocked by Encrypt Network Traffic
is blocked by Audit
is blocked by Software Process and Device Authentication
is blocked by Filter Network Traffic
is blocked by Encrypt Sensitive Information
is blocked by Access Management
is blocked by Communication Authenticity
is blocked by Network Segmentation
is blocked by Network Allowlists
is blocked by Detection of System Firmware
is blocked by Boot Integrity
is blocked by Update Software
is blocked by Code Signing
Impressum Deutsch Englisch