Standardlikelihood: Mediumseverity: HighDraft
CAPEC-36Using Unpublished Interfaces or Functionality
Abstraction
Standard
Status
Draft
Likelihood
Medium
Severity
High
Description
An adversary searches for and invokes interfaces or functionality that the target system designers did not intend to be publicly available. If interfaces fail to authenticate requests, the attacker may be able to invoke functionality they are not authorized for.
Metadata: standard CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-306, CWE-693, CWE-695, CWE-1242. Related CAPEC pattern: [object Object].
Related weaknesses· 4
Related attack patterns· 1
Exploits4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Missing Authentication for Critical Functioncwe-306 | 100% | live |
| Weakness | Inclusion of Undocumented Features or Chicken Bitscwe-1242 | 100% | live |
| Weakness | Use of Low-Level Functionalitycwe-695 | 100% | live |
| Weakness | Protection Mechanism Failurecwe-693 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.