Metaseverity: MediumDraft
CAPEC-115Authentication Bypass
Abstraction
Meta
Status
Draft
Severity
Medium
Description
An attacker gains access to application, service, or device with the privileges of an authorized or privileged user by evading or circumventing an authentication mechanism. The attacker is therefore able to access protected data without authentication ever having taken place.
Metadata: meta CAPEC pattern, status draft, severity medium. Underlying weakness: CWE-287. Mapped ATT&CK technique: [object Object].
Related weaknesses· 1
MITRE ATT&CK crosswalk· 1
Exploits1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Authenticationcwe-287 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Abuse Elevation Control Mechanismt1548 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.