| Home > CAPEC List > CAPEC-22: Exploiting Trust in Client (Version 3.9) |
|
High
High
| Nature | Type | ID | Name |
|---|---|---|---|
| ParentOf | Standard Attack PatternStandard Attack Pattern - A standard level attack pattern in CAPEC is focused on a specific methodology or technique used in an attack. It is often seen as a singular piece of a fully executed attack. A standard attack pattern is meant to provide sufficient details to understand the specific technique and how it attempts to accomplish a desired goal. A standard level attack pattern is a specific type of a more abstract meta level attack pattern. | 39 | Manipulating Opaque Client-based Data Tokens |
| ParentOf | Standard Attack PatternStandard Attack Pattern - A standard level attack pattern in CAPEC is focused on a specific methodology or technique used in an attack. It is often seen as a singular piece of a fully executed attack. A standard attack pattern is meant to provide sufficient details to understand the specific technique and how it attempts to accomplish a desired goal. A standard level attack pattern is a specific type of a more abstract meta level attack pattern. | 77 | Manipulating User-Controlled Variables |
| ParentOf | Standard Attack PatternStandard Attack Pattern - A standard level attack pattern in CAPEC is focused on a specific methodology or technique used in an attack. It is often seen as a singular piece of a fully executed attack. A standard attack pattern is meant to provide sufficient details to understand the specific technique and how it attempts to accomplish a desired goal. A standard level attack pattern is a specific type of a more abstract meta level attack pattern. | 202 | Create Malicious Client |
| ParentOf | Standard Attack PatternStandard Attack Pattern - A standard level attack pattern in CAPEC is focused on a specific methodology or technique used in an attack. It is often seen as a singular piece of a fully executed attack. A standard attack pattern is meant to provide sufficient details to understand the specific technique and how it attempts to accomplish a desired goal. A standard level attack pattern is a specific type of a more abstract meta level attack pattern. | 207 | Removing Important Client Functionality |
| View Name | Top Level Categories |
|---|---|
| Domains of Attack | Software, Communications |
| Mechanisms of Attack | Subvert Access Control |
| Scope | Impact | Likelihood |
|---|---|---|
Confidentiality Integrity Availability | Execute Unauthorized Commands | |
Confidentiality Access Control Authorization | Gain Privileges | |
Confidentiality | Read Data |
| CWE-ID | Weakness Name |
|---|---|
| 290 | Authentication Bypass by Spoofing |
| 287 | Improper Authentication |
| 20 | Improper Input Validation |
| 200 | Exposure of Sensitive Information to an Unauthorized Actor |
| 693 | Protection Mechanism Failure |
| Submissions | |||
|---|---|---|---|
| Submission Date | Submitter | Organization | |
| 2014年06月23日 (Version 2.6) | CAPEC Content Team | The MITRE Corporation | |
| Modifications | |||
| Modification Date | Modifier | Organization | |
| 2015年12月07日 (Version 2.8) | CAPEC Content Team | The MITRE Corporation | |
| Updated Description Summary, Related_Attack_Patterns | |||
| 2019年09月30日 (Version 3.2) | CAPEC Content Team | The MITRE Corporation | |
| Updated Description | |||
| Previous Entry Names | |||
| Change Date | Previous Entry Name | ||
| 2015年12月07日 (Version 2.8) | Exploiting Trust in Client (aka Make the Client Invisible) | ||
|
Use of the Common Attack Pattern Enumeration and Classification (CAPEC), and the associated references from this website are subject to the Terms of Use. Copyright © 2007–2025, The MITRE Corporation. CAPEC and the CAPEC logo are trademarks of The MITRE Corporation. |
||