CAPEC-441: Malicious Logic Insertion

Meta Stable 严重程度: High 攻击可能性: Medium

CAPEC版本: 3.9

更新日期: 2023-01-24

攻击模式描述

An adversary installs or adds malicious logic (also known as malware) into a seemingly benign component of a fielded system. This logic is often hidden from the user of the system and works behind the scenes to achieve negative impacts. With the proliferation of mass digital storage and inexpensive multimedia devices, Bluetooth and 802.11 support, new attack vectors for spreading malware are emerging for things we once thought of as innocuous greeting cards, picture frames, or digital projectors. This pattern of attack focuses on systems already fielded and used in operation as opposed to systems and their components that are still under development and part of the supply chain.

前提条件

  • Access to the component currently deployed at a victim location.

后果影响

影响范围: Authorization

技术影响: Execute Unauthorized Commands

关键信息

CAPEC ID: CAPEC-441

抽象级别: Meta

状态: Stable

典型严重程度: High

攻击可能性: Medium

相关CWE弱点