Standardlikelihood: Mediumseverity: MediumDraft
CAPEC-196Session Credential Falsification through Forging
Abstraction
Standard
Status
Draft
Likelihood
Medium
Severity
Medium
Description
An attacker creates a false but functional session credential in order to gain or usurp access to a service. Session credentials allow users to identify themselves to a service after an initial authentication without needing to resend the authentication information (usually a username and password) with every message. If an attacker is able to forge valid session credentials they may be able to bypass authentication or piggy-back off some other authenticated user's session. This attack differs from Reuse of Session IDs and Session Sidejacking attacks in that in the latter attacks an attacker uses a previous or existing credential without modification while, in a forging attack, the attacker must create their own credential, although it may be based on previously observed credentials.
Related weaknesses· 2
MITRE ATT&CK crosswalk· 3
Related attack patterns· 3
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Control of a Resource Through its Lifetimecwe-664 | 100% | live |
| Weakness | Session Fixationcwe-384 | 100% | live |
Related to3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Make and Impersonate Tokent1134.003 | 100% | live |
| SubTechnique | Create Process with Tokent1134.002 | 100% | live |
| Technique | Forge Web Credentialst1606 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.