CAPEC-115 Authentication Bypass

CAPEC ID: 115

CAPEC-115 Metadata

Likelihood of Attack

Medium

Typical Severity

Medium

Overview

Summary

An attacker gains access to application, service, or device with the privileges of an authorized or privileged user by evading or circumventing an authentication mechanism. The attacker is therefore able to access protected data without authentication ever having taken place.

Prerequisites

An authentication mechanism or subsystem implementing some form of authentication such as passwords, digest authentication, security certificates, etc.

Potential Solutions / Mitigations

No specific solutions listed.

Related Weaknesses (CWE)

CWE ID Description
CWE-287 Improper Authentication

Taxonomy Mappings

Taxonomy: ATTACK

Entry ID Entry Name
1548 Abuse Elevation Control Mechanism

Stay Ahead of Attack Patterns

Understanding CAPEC patterns helps security professionals anticipate and thwart potential attacks. Leverage these insights to enhance threat modeling, strengthen your software development lifecycle, and train your security teams effectively.