Metalikelihood: Highseverity: HighDraft
CAPEC-22Exploiting Trust in Client
Abstraction
Meta
Status
Draft
Likelihood
High
Severity
High
Description
An attack of this type exploits vulnerabilities in client/server communication channel authentication and data integrity. It leverages the implicit trust a server places in the client, or more importantly, that which the server believes is the client. An attacker executes this type of attack by communicating directly with the server where the server believes it is communicating only with a valid client. There are numerous variations of this type of attack.
Related weaknesses· 5
Exploits5
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Authentication Bypass by Spoofingcwe-290 | 100% | live |
| Weakness | Improper Input Validationcwe-20 | 100% | live |
| Weakness | Protection Mechanism Failurecwe-693 | 100% | live |
| Weakness | Improper Authenticationcwe-287 | 100% | live |
| Weakness | Exposure of Sensitive Information to an Unauthorized Actorcwe-200 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.