Adversaries may install an older version of the operating system of a network device to weaken security. Older operating system versions on network devices often have weaker encryption ciphers and, in general, fewer/less updated defensive features. (Citation: Cisco Synful Knock Evolution) On embedded devices, downgrading the version typically only requires replacing the operating system file in storage. With most embedded devices, this can be achieved by downloading a copy of the desired version of the operating system file and reconfiguring the device to boot from that file on next system restart. The adversary could then restart the device to implement the change immediately or they could wait until the next time the system restarts. Downgrading the system image to an older versions may allow an adversary to evade defenses by enabling behaviors such as [Weaken Encryption](https://attack.mitre.org/techniques/T1600). Downgrading of a system image can be done on its own, or it can be used in conjunction with [Patch System Image](https://attack.mitre.org/techniques/T1601/001).

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Detection Strategy for Downgrade System Image on Network Devices
is blocked by Multi-factor Authentication
is blocked by Code Signing
is blocked by Credential Access Protection
is blocked by Privileged Account Management
is blocked by Password Policies
is blocked by Boot Integrity
is blocked by Asset Inventories
is blocked by Provenance
is blocked by Configuration Change Control
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Authenticator Management
is blocked by Cryptographic Module Authentication
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Non-Modifiable Executable Programs
is blocked by Criticality Analysis During Development
is blocked by Security, Compliance & Resilience Testing Throughout Development
is blocked by Product Tampering and Counterfeiting (PTC)
is blocked by Developer Configuration Management
is blocked by Acquisition Strategies, Tools & Methods
is blocked by Software & Firmware Patching
Impressum Deutsch Englisch