Metaseverity: HighDraft
CAPEC-112Brute Force
Abstraction
Meta
Status
Draft
Severity
High
Description
In this attack, some asset (information, functionality, identity, etc.) is protected by a finite secret value. The attacker attempts to gain access to this asset by using trial-and-error to exhaustively explore all the possible secret values in the hope of finding the secret (or a value that is functionally equivalent) that will unlock the asset.
Related weaknesses· 3
MITRE ATT&CK crosswalk· 1
Exploits3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Use of Insufficiently Random Valuescwe-330 | 100% | live |
| Weakness | Weak Password Requirementscwe-521 | 100% | live |
| Weakness | Inadequate Encryption Strengthcwe-326 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Brute Forcet1110 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.