Umbra Wiki attack-pattern attack-pattern/CAPEC-115
Back to wiki

CAPEC-115 — Authentication Bypass

provenance: imported · ATT&CK: T1548 · CWE: CWE-287

CAPEC-115: Authentication Bypass

MITRE CAPEC attack pattern

Status Draft
Typical severity Medium
Likelihood of attack
Catalogue CAPEC 3.9 (2023-01-24)

Description

An attacker gains access to application, service, or device with the privileges of an authorized or privileged user by evading or circumventing an authentication mechanism. The attacker is therefore able to access protected data without authentication ever having taken place.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-287

ATT&CK techniques: T1548

Prerequisites

  • An authentication mechanism or subsystem implementing some form of authentication such as passwords, digest authentication, security certificates, etc.

Source