CAPEC Definitions

    CAPEC Definitions / CAPEC-638

    CAPEC-638: Altered Component Firmware

    An adversary exploits systems features and/or improperly protected firmware of hardware components, such as Hard Disk Drives (HDD), with the goal of executing malicious code from within the component's Master Boot Record (MBR). Conducting this type of attack entails the adversary infecting the target with firmware altering malware, using known tools, and a payload. Once this malware is executed, the MBR is modified to include instructions to execute the payload at desired intervals and when the system is booted up. A successful attack will obtain persistence within the victim system even if the operating system is reinstalled and/or if the component is formatted or has its data erased.

    Severity:Very High
    Possibility:Low

    Extended Description

    No Extended Description.

    Mitigations

    Leverage hardware components known to not be susceptible to these types of attacks.

    Implement hardware RAID infrastructure.

    Relationships with other CAPECs

    CAPEC-452: Infected Hardware

    Prerequisites

    Advanced knowledge about the target component's firmware

    Advanced knowledge about Master Boot Records (MBR)

    Advanced knowledge about tools used to insert firmware altering malware.

    Advanced knowledge about component shipments to the target organization.

    Related Weaknesses

    No related Weaknesses found.

    CAPEC-638: Altered Component Firmware | CVE-DB