StandardDraft
CAPEC-625Mobile Device Fault Injection
Abstraction
Standard
Status
Draft
Description
Fault injection attacks against mobile devices use disruptive signals or events (e.g. electromagnetic pulses, laser pulses, clock glitches, etc.) to cause faulty behavior. When performed in a controlled manner on devices performing cryptographic operations, this faulty behavior can be exploited to derive secret key information. Although this attack usually requires physical control of the mobile device, it is non-destructive, and the device can be used after the attack without any indication that secret keys were compromised.
Related weaknesses· 8
Related attack patterns· 1
Exploits8
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Restriction of Software Interfaces to Hardware Featurescwe-1256 | 100% | live |
| Weakness | Improper Handling of Faults that Lead to Instruction Skipscwe-1332 | 100% | live |
| Weakness | Improper Protection against Electromagnetic Fault Injection (EM-FI)cwe-1319 | 100% | live |
| Weakness | Semiconductor Defects in Hardware Logic with Security-Sensitive Implicationscwe-1248 | 100% | live |
| Weakness | Unauthorized Error Injection Can Degrade Hardware Redundancycwe-1334 | 100% | live |
| Weakness | Improper Handling of Hardware Behavior in Exceptionally Cold Environmentscwe-1351 | 100% | live |
| Weakness | Improper Protection Against Voltage and Clock Glitchescwe-1247 | 100% | live |
| Weakness | Improper Protections Against Hardware Overheatingcwe-1338 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.