Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP). The MIB is a configuration repository that stores variable information accessible via SNMP in the form of object identifiers (OID). Each OID identifies a variable that can be read or set and permits active management tasks, such as configuration changes, through remote modification of these variables. SNMP can give administrators great insight in their systems, such as, system information, description of hardware, physical location, and software packages(Citation: SANS Information Security Reading Room Securing SNMP Securing SNMP). The MIB may also contain device operational information, including running configuration, routing table, and interface details. Adversaries may use SNMP queries to collect MIB content directly from SNMP-managed devices in order to collect network information that allows the adversary to build network maps and facilitate future targeted exploitation.(Citation: US-CERT-TA18-106A)(Citation: Cisco Blog Legacy Device Attacks)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Software Configuration
is blocked by Update Software
is blocked by Encrypt Sensitive Information
is blocked by Detection Strategy for SNMP (MIB Dump) on Network Devices
is blocked by Network Intrusion Prevention
is blocked by Network Segmentation
is blocked by Filter Network Traffic
is blocked by Asset Inventories
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Transmission Confidentiality
is blocked by Transmission Integrity
is blocked by Encrypting Data At Rest
is blocked by Cybersecurity & Data Protection Attributes
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Media & Data Retention
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Identification & Authentication for Devices
is blocked by Identifier Management (User Names)
is blocked by Access Enforcement
is blocked by Access Control For Mobile Devices
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Remote Access
is blocked by Wireless Networking
is blocked by Security Function Isolation
is blocked by Information In Shared Resources
is blocked by Information Output Filtering
is blocked by Input Data Validation
Impressum Deutsch Englisch