Adversaries may access network configuration files to collect sensitive data about the device and the network. The network configuration is a file containing parameters that determine the operation of the device. The device typically stores an in-memory copy of the configuration while operating, and a separate configuration on non-volatile storage to load after device reset. Adversaries can inspect the configuration files to reveal information about the target network and its layout, the network device and its software, or identifying legitimate accounts and credentials for later use. Adversaries can use common management tools and protocols, such as Simple Network Management Protocol (SNMP) and Smart Install (SMI), to access network configuration files.(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)(Citation: Cisco Blog Legacy Device Attacks) These tools may be used to query specific data from a configuration repository or configure the device to export the configuration for later analysis.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Detection Strategy for Network Device Configuration Dump via Config Repositories
is blocked by Encrypt Sensitive Information
is blocked by Network Segmentation
is blocked by Network Intrusion Prevention
is blocked by Software Configuration
is blocked by Filter Network Traffic
is blocked by Update Software
is blocked by Asset Inventories
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Transmission Confidentiality
is blocked by Transmission Integrity
is blocked by Encrypting Data At Rest
is blocked by Cybersecurity & Data Protection Attributes
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Media & Data Retention
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Identification & Authentication for Devices
is blocked by Identifier Management (User Names)
is blocked by Access Enforcement
is blocked by Access Control For Mobile Devices
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Remote Access
is blocked by Wireless Networking
is blocked by Security Function Isolation
is blocked by Information In Shared Resources
is blocked by Information Output Filtering
is blocked by Input Data Validation
Impressum German English