Metaseverity: MediumDraft
CAPEC-114Authentication Abuse
Abstraction
Meta
Status
Draft
Severity
Medium
Description
An attacker obtains unauthorized access to an application, service or device either through knowledge of the inherent weaknesses of an authentication mechanism, or by exploiting a flaw in the authentication scheme's implementation. In such an attack an authentication mechanism is functioning but a carefully controlled sequence of events causes the mechanism to grant access to the attacker.
Related weaknesses· 2
MITRE ATT&CK crosswalk· 1
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Authenticationcwe-287 | 100% | live |
| Weakness | Internal Asset Exposed to Unsafe Debug Access Level or Statecwe-1244 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Abuse Elevation Control Mechanismt1548 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.