Applied Cybernetics Group
T1190 — Exploit Public-Facing Application
- Technique
T1190- Tactics
- Initial Access
- MISP citations
- 0
- KEV CVEs mapped
- 157
- Community rules
- 146
- thrunt rules
- 0
- Upstream
- https://attack.mitre.org/techniques/T1190
MITRE description
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets.(Citation: NVD CVE-2016-6662)(Citation: CIS Multiple SMB Vulnerabilities)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)(Citation: Cisco Blog Legacy Device Attacks)(Citation: NVD CVE-2014-7169) On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.(Citation: Recorded Future ESXiArgs Ransomware 2023)(Citation: Ars Technica VMWare Code Execution Vulnerability 2021) Depending on the flaw being exploited, this may also involve [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203). If an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the [Cloud Instance Metadata API](https://attack.mitre.org/techniques/T1552/005)), exploit container host access via [Escape to Host](https://attack.mitre.org/techniques/T1611), or take advantage of weak identity and access management policies. Adversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses.(Citation: Mandiant Fortinet Zero Day)(Citation: Wired Russia Cyberwar) For websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.(Citation: OWASP Top 10)(Citation: CWE top 25)
KEV CVEs mapped to this technique
Per MITRE CTID's hand-curated KEV→ATT&CK mappings — these are the actively-exploited vulnerabilities behind this technique's KEV signal.
CVE-2025-5777CVE-2025-53770CVE-2025-49706CVE-2025-49704CVE-2025-4428CVE-2025-4427CVE-2025-42999CVE-2025-42599CVE-2025-35939CVE-2025-34028CVE-2025-25257CVE-2025-23006CVE-2025-22457CVE-2025-1316CVE-2025-0282CVE-2025-0108CVE-2024-57727CVE-2024-55550CVE-2024-4879CVE-2024-48248CVE-2024-4577CVE-2024-4358CVE-2024-38475CVE-2024-34102CVE-2024-27198CVE-2024-21893CVE-2024-21887CVE-2024-21762CVE-2024-20953CVE-2024-20353CVE-2024-13161CVE-2024-13160CVE-2024-13159CVE-2024-0769CVE-2023-7101CVE-2023-49103CVE-2023-48788CVE-2023-48365CVE-2023-46805CVE-2023-46604CVE-2023-44487CVE-2023-42793CVE-2023-38950CVE-2023-38205CVE-2023-38203CVE-2023-38035CVE-2023-36851CVE-2023-36847CVE-2023-36846CVE-2023-36845CVE-2023-36844CVE-2023-3519CVE-2023-35081CVE-2023-35078CVE-2023-34362CVE-2023-33246CVE-2023-29492CVE-2023-29300CVE-2023-29298CVE-2023-27997CVE-2023-27524CVE-2023-27350CVE-2023-26360CVE-2023-26359CVE-2023-22952CVE-2023-22518CVE-2023-22515CVE-2023-20887CVE-2023-20198CVE-2023-0669CVE-2022-47966CVE-2022-43939CVE-2022-42948CVE-2022-42475CVE-2022-40684CVE-2022-39197CVE-2022-36804CVE-2022-35914CVE-2022-29464CVE-2022-28810CVE-2022-26501CVE-2022-26500CVE-2022-26258CVE-2022-26134CVE-2022-24086CVE-2022-23131CVE-2022-22965CVE-2022-22963CVE-2022-22947CVE-2022-20821CVE-2022-20708CVE-2022-20700CVE-2022-1040CVE-2022-0028CVE-2021-45382CVE-2021-44529CVE-2021-44515CVE-2021-44228CVE-2021-44077CVE-2021-40655CVE-2021-40539CVE-2021-39226CVE-2021-39144CVE-2021-37415CVE-2021-36380CVE-2021-35464CVE-2021-35394CVE-2021-34523CVE-2021-34473CVE-2021-3129CVE-2021-31166CVE-2021-27860CVE-2021-27104CVE-2021-27103CVE-2021-27102CVE-2021-27065CVE-2021-26858CVE-2021-26085CVE-2021-22986CVE-2021-22893CVE-2021-22205CVE-2021-22204CVE-2021-22017CVE-2021-22005CVE-2021-21975CVE-2021-21973CVE-2021-21972CVE-2020-5902CVE-2020-29557CVE-2020-17530CVE-2020-15505CVE-2020-0688CVE-2019-18935CVE-2019-17558CVE-2019-1653CVE-2019-11634CVE-2019-0604CVE-2018-7600CVE-2018-6789CVE-2018-4939CVE-2018-15961CVE-2018-13379CVE-2018-11776CVE-2017-9822CVE-2017-9805CVE-2017-5638CVE-2017-12637CVE-2016-4437CVE-2016-10033CVE-2014-7169CVE-2014-6271CVE-2013-0632CVE-2013-0631CVE-2013-0629CVE-2013-0625CVE-2010-2861CVE-2009-3960
Detection coverage
SigmaHQ community rules
- CVE-2010-5278 Exploitation Attempt (emerging-threats)
- Rejetto HTTP File Server RCE (emerging-threats)
- Fortinet CVE-2018-13379 Exploitation (emerging-threats)
- Oracle WebLogic Exploit (emerging-threats)
- Pulse Secure Attack CVE-2019-11510 (emerging-threats)
- Citrix Netscaler Attack CVE-2019-19781 (emerging-threats)
- Confluence Exploitation CVE-2019-3398 (emerging-threats)
- CVE-2020-0688 Exploitation Attempt (emerging-threats)
- CVE-2020-0688 Exchange Exploitation via Web Log (emerging-threats)
- CVE-2020-0688 Exploitation via Eventlog (emerging-threats)
- CVE-2020-10148 SolarWinds Orion API Auth Bypass (emerging-threats)
- Exploited CVE-2020-10189 Zoho ManageEngine (emerging-threats)
- DNS RCE CVE-2020-1350 (emerging-threats)
- Oracle WebLogic Exploit CVE-2020-14882 (emerging-threats)
- TerraMaster TOS CVE-2020-28188 (emerging-threats)
- Cisco ASA FTD Exploit CVE-2020-3452 (emerging-threats)
- CVE-2020-5902 F5 BIG-IP Exploitation Attempt (emerging-threats)
- Citrix ADS Exploitation CVE-2020-8193 CVE-2020-8195 (emerging-threats)
- Arcadyan Router Exploitations (emerging-threats)
- Oracle WebLogic Exploit CVE-2021-2109 (emerging-threats)
- CVE-2021-21972 VSphere Exploitation (emerging-threats)
- CVE-2021-21978 Exploitation Attempt (emerging-threats)
- VMware vCenter Server File Upload CVE-2021-22005 (emerging-threats)
- Fortinet CVE-2021-22123 Exploitation (emerging-threats)
- Pulse Connect Secure RCE Attack CVE-2021-22893 (emerging-threats)
Showing 25 of 146 community rules —
the full set is tagged attack.t1190 in
SigmaHQ.