Threat Sg.TA.LTethSg2AC.1

URI: Sg.TA.LTethSg2AC.1

Package: LocalDeviceConnectivity

< prev | next >

Description: Tethering re-enabled between Gateway and Host connecting to LogicalSubnet: if an attacker has control of host Gateway in a context where it is paired with Host and connected to LogicalSubnet, then they can tether Gateway and connect Host to LogicalSubnet.

Threat Type: Primary Threat

Matching Pattern:

Sg.TA.LTethSg2AC.1
MP-LTethSg2AC

Finds a Host connected via a layer 1 subnet (i.e., Bluetooth or USB) connection and a tethered gateway to an IP subnet, plus the forward and reverse path segment via the gateway, and a context in which the gateway is connected to both subnets.

        (empty)

        (empty)

        CSG-DisableTethering

        (empty)