BaseDraft
CWE-301Reflection Attack in an Authentication Protocol
Category: auth
Description
Simple authentication protocols are subject to reflection attacks if a malicious user can use the target machine to impersonate a trusted user.
Common consequences· 1
- Access Control — Gain Privileges or Assume IdentityThe primary result of reflection attacks is successful authentication with a target machine -- as an impersonated user.
Potential mitigations· 2
- [Architecture and Design]Use different keys for the initiator and responder or of a different type of challenge for the initiator and responder.
- [Architecture and Design]Let the initiator prove its identity before proceeding.
Related CAPEC attack patterns· 1
References
Exploits (incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Reflection Attack in Authentication Protocolcapec-90 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.