kevmap

TechniquesT1190 › AN0225

AN0225 Analytic 0225

Network Devices · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary exploits public admin services on routers/firewalls/switches. Chain: anomalous HTTP/SNMP/SmartInstall inputs → device syslog errors/restarts → config changes/CLI spawn → egress to attacker C2.</p>
Detects
T1190 Exploit Public-Facing Application
Part of
DET0080 Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
networkdevice:controlplaneSyslog from edge devices with HTTP 500s on mgmt portal, SmartInstall events, unexpected CLI commandsDC0038 Application Log Content
NSM:FlowNetFlow/sFlow for odd egress to Internet from mgmt planeDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MgmtPortsList of admin services to watch (8443, 443, 161/udp, 4786, 22).
TrustedAdminsAdmin source ranges to allow.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-3960Adobe BlazeDSMapped
CVE-2010-2861Adobe ColdFusionMapped
CVE-2013-0625Adobe ColdFusionMapped
CVE-2013-0629Adobe ColdFusionMapped
CVE-2013-0631Adobe ColdFusionMapped
CVE-2013-0632Adobe ColdFusionMapped
CVE-2014-6271GNU Bourne-Again Shell (Bash)Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash)Mapped
CVE-2016-10033PHP PHPMailerMapped
CVE-2016-4437Apache ShiroMapped
CVE-2017-12637SAP NetWeaverMapped
CVE-2017-5638Apache StrutsMapped
CVE-2017-9805Apache StrutsMapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN)Mapped
CVE-2018-11776Apache StrutsMapped
CVE-2018-13379Fortinet FortiOSMapped
CVE-2018-15961Adobe ColdFusionMapped
CVE-2018-4939Adobe ColdFusionMapped
CVE-2018-6789Exim EximMapped
CVE-2018-7600Drupal Drupal CoreMapped
CVE-2019-0604Microsoft SharePointMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2019-1653Cisco Small Business RV320 and RV325 RoutersMapped
CVE-2019-17558Apache SolrMapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAXMapped
CVE-2020-0688Microsoft Exchange ServerMapped
CVE-2020-15505Ivanti MobileIron Multiple ProductsMapped
CVE-2020-17530Apache StrutsMapped
CVE-2020-29557D-Link DIR-825 R1 DevicesMapped
CVE-2020-5902F5 BIG-IPStale
CVE-2021-21972VMware vCenter ServerMapped
CVE-2021-21973VMware vCenter Server and Cloud FoundationMapped
CVE-2021-21975VMware vRealize Operations Manager APIMapped
CVE-2021-22005VMware vCenter ServerMapped
CVE-2021-22017VMware vCenter ServerMapped
CVE-2021-22204Perl ExiftoolMapped
CVE-2021-22205GitLab Community and Enterprise EditionsMapped
CVE-2021-22893Ivanti Pulse Connect SecureMapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized ManagementMapped
CVE-2021-26085Atlassian Confluence ServerMapped
CVE-2021-26858Microsoft Exchange ServerMapped
CVE-2021-27065Microsoft Exchange ServerMapped
CVE-2021-27102Accellion FTAMapped
CVE-2021-27103Accellion FTAMapped
CVE-2021-27104Accellion FTAMapped
CVE-2021-27860FatPipe WARP, IPVPN, and MPVPN softwareMapped
CVE-2021-31166Microsoft HTTP Protocol StackMapped
CVE-2021-3129Laravel IgnitionMapped
CVE-2021-34473Microsoft Exchange ServerMapped
CVE-2021-34523Microsoft Exchange ServerMapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK)Mapped
CVE-2021-35464ForgeRock Access Management (AM)Mapped
CVE-2021-36380Sunhillo SureLineMapped
CVE-2021-37415Zoho ManageEngine ServiceDesk Plus (SDP)Mapped
CVE-2021-39144XStream XStreamMapped
CVE-2021-39226Grafana Labs GrafanaMapped
CVE-2021-40539Zoho ManageEngineMapped
CVE-2021-40655D-Link DIR-605 RouterMapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusMapped
CVE-2021-44228Apache Log4j2Mapped
CVE-2021-44515Zoho Desktop CentralMapped
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA)Mapped
CVE-2021-45382D-Link Multiple RoutersMapped
CVE-2022-0028Palo Alto Networks PAN-OSMapped
CVE-2022-1040Sophos FirewallMapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-20821Cisco IOS XRMapped
CVE-2022-22947VMware Spring Cloud GatewayMapped
CVE-2022-22963VMware Tanzu Spring CloudMapped
CVE-2022-22965VMware Spring FrameworkMapped
CVE-2022-23131Zabbix FrontendMapped
CVE-2022-24086Adobe Commerce and Magento Open SourceMapped
CVE-2022-26134Atlassian Confluence Server/Data CenterMapped
CVE-2022-26258D-Link DIR-820LMapped
CVE-2022-26500Veeam Backup & ReplicationMapped
CVE-2022-26501Veeam Backup & ReplicationMapped
CVE-2022-28810Zoho ManageEngineMapped
CVE-2022-29464WSO2 Multiple ProductsMapped
CVE-2022-35914Teclib GLPIMapped
CVE-2022-36804Atlassian Bitbucket Server and Data CenterMapped
CVE-2022-39197Fortra Cobalt StrikeMapped
CVE-2022-40684Fortinet Multiple ProductsMapped
CVE-2022-42475Fortinet FortiOSMapped
CVE-2022-42948Fortra Cobalt StrikeMapped
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) ServerMapped
CVE-2022-47966Zoho ManageEngineMapped
CVE-2023-0669Fortra GoAnywhere MFTMapped
CVE-2023-20198Cisco IOS XE Web UIMapped
CVE-2023-20887VMware Aria Operations for NetworksMapped
CVE-2023-22515Atlassian Confluence Data Center and ServerMapped
CVE-2023-22518Atlassian Confluence Data Center and ServerMapped
CVE-2023-22952SugarCRM Multiple ProductsStale
CVE-2023-26359Adobe ColdFusionMapped
CVE-2023-26360Adobe ColdFusionMapped
CVE-2023-27350PaperCut MF/NGMapped
CVE-2023-27524Apache SupersetMapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPNMapped
CVE-2023-29298Adobe ColdFusionMapped
CVE-2023-29300Adobe ColdFusionMapped
CVE-2023-29492Novi Survey Novi SurveyMapped
CVE-2023-33246Apache RocketMQMapped
CVE-2023-34362Progress MOVEit TransferMapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler GatewayMapped
CVE-2023-36844Juniper Junos OSMapped
CVE-2023-36845Juniper Junos OSMapped
CVE-2023-36846Juniper Junos OSMapped
CVE-2023-36847Juniper Junos OSMapped
CVE-2023-36851Juniper Junos OSMapped
CVE-2023-38035Ivanti SentryMapped
CVE-2023-38203Adobe ColdFusionMapped
CVE-2023-38205Adobe ColdFusionMapped
CVE-2023-38950ZKTeco BioTimeMapped
CVE-2023-42793JetBrains TeamCityMapped
CVE-2023-44487IETF HTTP/2Mapped
CVE-2023-46604Apache ActiveMQMapped
CVE-2023-46805Ivanti Connect Secure and Policy SecureMapped
CVE-2023-48365Qlik SenseMapped
CVE-2023-48788Fortinet FortiClient EMSMapped
CVE-2023-49103ownCloud ownCloud graphapiMapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcelMapped
CVE-2024-0769D-Link DIR-859 RouterMapped
CVE-2024-13159Ivanti Endpoint Manager (EPM)Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM)Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM)Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Mapped
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM)Mapped
CVE-2024-21762Fortinet FortiOSMapped
CVE-2024-21887Ivanti Connect Secure and Policy SecureMapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and NeuronsMapped
CVE-2024-27198JetBrains TeamCityMapped
CVE-2024-34102Adobe Commerce and Magento Open SourceMapped
CVE-2024-38475Apache HTTP ServerMapped
CVE-2024-4358Progress Telerik Report ServerMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-48248NAKIVO Backup and ReplicationMapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now PlatformMapped
CVE-2024-55550Mitel MiCollabMapped
CVE-2024-57727SimpleHelp SimpleHelpMapped
CVE-2025-0108Palo Alto Networks PAN-OSMapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA GatewaysMapped
CVE-2025-1316Edimax IC-7100 IP CameraMapped
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA GatewaysMapped
CVE-2025-23006SonicWall SMA1000 AppliancesMapped
CVE-2025-25257Fortinet FortiWebMapped
CVE-2025-34028Commvault Command CenterMapped
CVE-2025-35939Craft CMS Craft CMSMapped
CVE-2025-42599Qualitia Active! MailMapped
CVE-2025-42999SAP NetWeaverMapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-49704Microsoft SharePointMapped
CVE-2025-49706Microsoft SharePointMapped
CVE-2025-53770Microsoft SharePointMapped
CVE-2025-5777Citrix NetScaler ADC and GatewayMapped