Standardlikelihood: Highseverity: HighDraft
CAPEC-141Cache Poisoning
Abstraction
Standard
Status
Draft
Likelihood
High
Severity
High
Description
An attacker exploits the functionality of cache technologies to cause specific data to be cached that aids the attackers' objectives. This describes any attack whereby an attacker places incorrect or harmful material in cache. The targeted cache can be an application's cache (e.g. a web browser cache) or a public cache (e.g. a DNS or ARP cache). Until the cache is refreshed, most applications or clients will treat the corrupted cache value as valid. This can lead to a wide range of exploits including redirecting web browsers towards sites that install malware and repeatedly incorrect calculations based on the incorrect value.
Related weaknesses· 4
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Acceptance of Extraneous Untrusted Data With Trusted Datacwe-349 | 100% | live |
| Weakness | Insufficient Verification of Data Authenticitycwe-345 | 100% | live |
| Weakness | Origin Validation Errorcwe-346 | 100% | live |
| Weakness | Use of Less Trusted Sourcecwe-348 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | ARP Cache Poisoningt1557.002 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.