Detailedseverity: MediumStable
CAPEC-633Token Impersonation
Abstraction
Detailed
Status
Stable
Severity
Medium
Description
An adversary exploits a weakness in authentication to create an access token (or equivalent) that impersonates a different entity, and then associates a process/thread to that that impersonated token. This action causes a downstream user to make a decision or take action that is based on the assumed identity, and not the response that blocks the adversary.
Related weaknesses· 2
MITRE ATT&CK crosswalk· 1
Related attack patterns· 1
Exploits2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Generation of Incorrect Security Tokenscwe-1270 | 100% | live |
| Weakness | Improper Authenticationcwe-287 | 100% | live |
Related to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Access Token Manipulationt1134 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.