Umbra Wiki attack-pattern attack-pattern/CAPEC-202
Back to wiki

CAPEC-202 — Create Malicious Client

provenance: imported · CWE: CWE-602

CAPEC-202: Create Malicious Client

MITRE CAPEC attack pattern

Status Draft
Typical severity Medium
Likelihood of attack
Catalogue CAPEC 3.9 (2023-01-24)

Description

An adversary creates a client application to interface with a target service where the client violates assumptions the service makes about clients. Services that have designated client applications (as opposed to services that use general client applications, such as IMAP or POP mail servers which can interact with any IMAP or POP client) may assume that the client will follow specific procedures.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

Weaknesses exploited: CWE-602

Prerequisites

  • The targeted service must make assumptions about the behavior of the client application that interacts with it, which can be abused by an adversary.

Source