Exploit Public-Facing Application

T1190

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers. Depending on the flaw being exploited, this may also involve Exploitation for Stealth or Exploitation for Client Execution.

If an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the Cloud Instance Metadata API), exploit container host access via Escape to Host, or take advantage of weak identity and access management policies.

Adversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses.

For websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.

Detection rules164

Rules on DetectionCode tagged with T1190.

Sigma49

RuleLevelLog source
Apache Spark Shell Command Injection - ProcessCreationhighlinux / process_creation
Atlassian Confluence CVE-2022-26134highlinux / process_creation
DNS Query to External Service Interaction DomainshighNULL / dns
Hack Tool User AgenthighNULL / proxy
Java Payload StringshighNULL / webserver
JNDIExploit PatternhighNULL / webserver
OMIGOD HTTP No Authentication RCEhighzeek / NULL
OMIGOD SCX RunAsProvider ExecuteScripthighlinux / process_creation
OMIGOD SCX RunAsProvider ExecuteShellCommandhighlinux / process_creation
OpenCanary - FTP Login Attempthighopencanary / application
OpenCanary - HTTP GET Requesthighopencanary / application
OpenCanary - HTTP POST Login Attempthighopencanary / application
Potential JNDI Injection Exploitation In JVM Based Applicationhighjvm / application
Potential Local File Read Vulnerability In JVM Based Applicationhighjvm / application
Potential OGNL Injection Exploitation In JVM Based Applicationhighjvm / application

Splunk115

RuleTypeRiskData source
Access to Vulnerable Ivanti Connect Secure Bookmark EndpointTTPNULLSuricata
Adobe ColdFusion Access Control BypassAnomalyNULLSuricata
Adobe ColdFusion Unauthenticated Arbitrary File ReadAnomalyNULLSuricata
Cisco IOS XE Implant AccessTTPNULLSuricata
Cisco IOS XE Request Platform Package Describe Shell PatternTTPNULLCisco IOS Logs
Cisco IOS XE WebUI Login From IOSd Local PortTTPNULLCisco IOS Logs
Cisco IOS XE WebUI Programmatic ConfigurationAnomalyNULLCisco IOS Logs
Cisco NVM - Webserver Download From File Sharing WebsiteTTPNULLCisco Network Visibility Module Flow Data
Cisco SD-WAN - Arbitrary File Overwrite Exploitation ActivityTTPNULLCisco SD-WAN Service Proxy Access Logs
Cisco SD-WAN - Low Frequency Rogue PeerAnomalyNULLCisco SD-WAN NTCE 1000001
Cisco SD-WAN - Peering ActivityHuntingNULLCisco SD-WAN NTCE 1000001
Cisco Secure Firewall - High Priority Intrusion ClassificationTTPNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Lumma Stealer ActivityTTPNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Oracle E-Business Suite CorrelationTTPNULLCisco Secure Firewall Threat Defense Intrusion Event
Cisco Secure Firewall - Oracle E-Business Suite ExploitationTTPNULLCisco Secure Firewall Threat Defense Intrusion Event

Groups46

Show 22 more

Software8

Campaigns21

Procedure examples75

Groups46

Used byProcedure example
GroupAgrius

Agrius exploits public-facing applications for initial access to victim environments. Examples include widespread attempts to exploit CVE-2018-13379 in FortiOS devices and SQL injection activity.

GroupAPT28

APT28 has used a variety of public exploits, including CVE 2020-0688 and CVE 2020-17144, to gain execution on vulnerable Microsoft Exchange; they have also conducted SQL injection attacks against external websites.

GroupAPT29

APT29 has exploited CVE-2019-19781 for Citrix, CVE-2019-11510 for Pulse Secure VPNs, CVE-2018-13379 for FortiGate VPNs, and CVE-2019-9670 in Zimbra software to gain access.

GroupAPT39

APT39 has used SQL injection for initial compromise.

GroupAPT41

APT41 exploited CVE-2020-10189 against Zoho ManageEngine Desktop Central through unsafe deserialization, and CVE-2019-19781 to compromise Citrix Application Delivery Controllers (ADC) and gateway devices. APT41 leveraged vulnerabilities such as ProxyLogon exploitation or SQL injection for initial access. APT41 exploited CVE-2021-26855 against a vulnerable Microsoft Exchange Server to gain initial access to the victim network.

GroupAPT5

APT5 has exploited vulnerabilities in externally facing software and devices including Pulse Secure VPNs and Citrix Application Delivery Controllers.

GroupAxiom

Axiom has been observed using SQL injection to gain access to systems.

GroupBackdoorDiplomacy

BackdoorDiplomacy has exploited CVE-2020-5902, an F5 BIP-IP vulnerability, to drop a Linux backdoor. BackdoorDiplomacy has also exploited mis-configured Plesk servers.

View all 46 groups examples

Software8

Used byProcedure example
MalwareBOLDMOVE

BOLDMOVE is associated with exploitation of CVE-2022-49475 in FortiOS.

MalwareCOATHANGER

COATHANGER is installed following exploitation of a vulnerable FortiGate device.

ToolHavij

Havij is used to automate SQL injection.

MalwareQilin

Qilin has been delivered through exploitation of exposed applications and interfaces including Citrix and RDP.

MalwareSiloscape

Siloscape is executed after the attacker gains initial access to a Windows container using a known vulnerability.

MalwareSoreFang

SoreFang can gain access by exploiting a Sangfor SSL VPN vulnerability that allows for the placement and delivery of malicious update binaries.

Toolsqlmap

sqlmap can be used to automate exploitation of SQL injection vulnerabilities.

MalwareZxShell

ZxShell has been dropped through exploitation of CVE-2011-2462, CVE-2013-3163, and CVE-2014-0322.

Campaigns21

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to deploy a custom exploit payload targeting an identified SSRF vulnerability to gain initial access to a targeted environment.

CampaignArcaneDoor

ArcaneDoor abused WebVPN traffic to targeted devices to achieve unauthorized remote code execution.

CampaignC0017

During C0017, APT41 exploited CVE-2021-44207 in the USAHerds application and CVE-2021-44228 in Log4j, as well as other .NET deserialization, SQL injection, and directory traversal vulnerabilities to gain initial access.

CampaignC0018

During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832.

CampaignC0027

During C0027, Scattered Spider exploited CVE-2021-35464 in the ForgeRock Open Access Management (OpenAM) application server to gain initial access.

CampaignCutting Edge

During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887.

CampaignFLORAHOX Activity

FLORAHOX Activity has exploited and infected vulnerable routers to recruit additional network devices into the ORB.

CampaignFrostyGoop Incident

FrostyGoop Incident was likely enabled by the adversary exploiting an unknown vulnerability in an external-facing router.

View all 21 campaigns examples

References11

  1. Ars Technica VMWare Code Execution Vulnerability 2021 Open source
    Dan Goodin . (2021, February 25). Code-execution flaw in VMware has a severity rating of 9.8 out of 10. Retrieved April 8, 2025.
  2. CIS Multiple SMB Vulnerabilities Open source
    CIS. (2017, May 15). Multiple Vulnerabilities in Microsoft Windows SMB Server Could Allow for Remote Code Execution. Retrieved April 3, 2018.
  3. CWE top 25 Open source
    Christey, S., Brown, M., Kirby, D., Martin, B., Paller, A.. (2011, September 13). 2011 CWE/SANS Top 25 Most Dangerous Software Errors. Retrieved April 10, 2019.
  4. Cisco Blog Legacy Device Attacks Open source
    Omar Santos. (2020, October 19). Attackers Continue to Target Legacy Devices. Retrieved October 20, 2020.
  5. Mandiant Fortinet Zero Day Open source
    Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.
  6. NVD CVE-2014-7169 Open source
    National Vulnerability Database. (2017, September 24). CVE-2014-7169 Detail. Retrieved April 3, 2018.
  7. NVD CVE-2016-6662 Open source
    National Vulnerability Database. (2017, February 2). CVE-2016-6662 Detail. Retrieved April 3, 2018.
  8. OWASP Top 10 Open source
    OWASP. (2018, February 23). OWASP Top Ten Project. Retrieved April 3, 2018.
  9. Recorded Future ESXiArgs Ransomware 2023 Open source
    German Hoeffner, Aaron Soehnen and Gianni Perez. (2023, February 7). ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers. Retrieved March 26, 2025.
  10. US-CERT TA18-106A Network Infrastructure Devices 2018 Open source
    US-CERT. (2018, April 20). Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.
  11. Wired Russia Cyberwar Open source
    Greenberg, A. (2022, November 10). Russia’s New Cyberwarfare in Ukraine Is Fast, Dirty, and Relentless. Retrieved March 22, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.