Detailedlikelihood: Mediumseverity: Very HighDraft

CAPEC-679Exploitation of Improperly Configured or Implemented Memory Protections

Abstraction
Detailed
Status
Draft
Likelihood
Medium
Severity
Very High

Description

Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity very high. Underlying weaknesses: CWE-1222, CWE-1252, CWE-1257, CWE-1260, CWE-1274 (and 4 more). Related CAPEC patterns: [object Object], [object Object]. Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity very high. Underlying weaknesses: CWE-1222, CWE-1252, CWE-1257, CWE-1260, CWE-1274 (and 4 more). Related CAPEC patterns: [object Object], [object Object].

Related weaknesses· 9

CWE-1222CWE-1252CWE-1257CWE-1260CWE-1274CWE-1282CWE-1312CWE-1316CWE-1326

Related attack patterns· 2

CAPEC-1 (ChildOf)CAPEC-180 (ChildOf)

Exploits9

TypeTargetConfidenceTier
WeaknessImproper Access Control Applied to Mirrored or Aliased Memory Regionscwe-1257100%live
WeaknessCPU Hardware Not Configured to Support Exclusivity of Write and Execute Operationscwe-1252100%live
WeaknessMissing Protection for Mirrored Regions in On-Chip Fabric Firewallcwe-1312100%live
WeaknessAssumed-Immutable Data is Stored in Writable Memorycwe-1282100%live
WeaknessFabric-Address Map Allows Programming of Unwarranted Overlaps of Protected and Unprotected Rangescwe-1316100%live
WeaknessInsufficient Granularity of Address Regions Protected by Register Lockscwe-1222100%live
WeaknessMissing Immutable Root of Trust in Hardwarecwe-1326100%live
WeaknessImproper Access Control for Volatile Memory Containing Boot Codecwe-1274100%live
WeaknessImproper Handling of Overlap Between Protected Memory Rangescwe-1260100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CAPEC
Exploitation of Improperly Controlled Registers
CAPEC
Exploitation of Improperly Controlled Hardware Security Identifiers
CAPEC
Exploiting Incorrect Chaining or Granularity of Hardware Debug Components
CAPEC
Exploit Non-Production Interfaces
CAPEC
Read Sensitive Constants Within an Executable
CAPEC
Target Programs with Elevated Privileges
Sourced from MITRE CAPEC. Curated by Adam Lundqvist, SQUR.