Metalikelihood: Mediumseverity: HighStable

CAPEC-441Malicious Logic Insertion

Abstraction
Meta
Status
Stable
Likelihood
Medium
Severity
High

Description

An adversary installs or adds malicious logic (also known as malware) into a seemingly benign component of a fielded system. This logic is often hidden from the user of the system and works behind the scenes to achieve negative impacts. With the proliferation of mass digital storage and inexpensive multimedia devices, Bluetooth and 802.11 support, new attack vectors for spreading malware are emerging for things we once thought of as innocuous greeting cards, picture frames, or digital projectors. This pattern of attack focuses on systems already fielded and used in operation as opposed to systems and their components that are still under development and part of the supply chain.

Related weaknesses· 1

CWE-284

Exploits1

TypeTargetConfidenceTier
WeaknessImproper Access Controlcwe-284100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Infected Software
CAPEC
Infected Hardware
CAPEC
Infected Memory
CAPEC
Malicious Software Implanted
CAPEC
Malicious Hardware Update
CAPEC
Malicious Logic Insertion into Product Software via Configuration Management Manipulation
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.