Umbra Wiki attack-pattern attack-pattern/CAPEC-166
Back to wiki

CAPEC-166 — Force the System to Reset Values

provenance: imported · CWE: CWE-306 CWE-1221 CWE-1232

CAPEC-166: Force the System to Reset Values

MITRE CAPEC attack pattern

Status Draft
Typical severity Medium
Likelihood of attack
Catalogue CAPEC 3.9 (2023-01-24)

Description

An attacker forces the target into a previous state in order to leverage potential weaknesses in the target dependent upon a prior configuration or state-dependent factors. Even in cases where an attacker may not be able to directly control the configuration of the targeted application, they may be able to reset the configuration to a prior state since many applications implement reset functions.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-306, CWE-1221, CWE-1232

Prerequisites

  • The targeted application must have a reset function that returns the configuration of the application to an earlier state.
  • The reset functionality must be inadequately protected against use.

Source