Unsecured Credentials: VPN Credential

Adversaries may search unsecured VPN credentials to gain unauthorized access to vehicle backend servers. These credentials are intended to protect the backend server and only allow legitimate vehicles to access it. However, if these VPN credentials are not properly secured, adversaries can easily extract them and directly connect to the backend server using without the legitimate vehicles.

ID: T2039.004
Sub-technique of:  T2039
Version: 1.0
Created: 03 December 2023
Last Modified: 03 December 2023

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.