Prerequisiti
Knowledge of the target device's or application’s vulnerabilities that can be capitalized on with malicious code. The adversary must be able to place the malicious code on the target device.
Competenze richieste
To deploy a hidden process or malware on the system to automatically collect audio and video data.
Mitigazioni
Prevent unknown code from executing on a system through the use of an allowlist policy.
Patch installed applications as soon as new updates become available.
Vulnerabilità correlate
| CWE-ID |
Nome della vulnerabilità |
|
Privilege Defined With Unsafe Actions A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity. |
Riferimenti
REF-653
What is Car Whisperer?
Amrita Mitra.
https://www.thesecuritybuddy.com/bluetooth-security/what-is-car-whisperer/ REF-654
What is Bluesnarfing?
https://www.finjanmobile.com/what-is-bluesnarfing/
Invio
| Nome |
Organizzazione |
Data |
Data di rilascio |
| CAPEC Content Team |
The MITRE Corporation |
2018-07-31 +00:00 |
|
Modifiche
| Nome |
Organizzazione |
Data |
Commento |
| CAPEC Content Team |
The MITRE Corporation |
2020-07-30 +00:00 |
Updated Mitigations, Related_Attack_Patterns |
| CAPEC Content Team |
The MITRE Corporation |
2021-06-24 +00:00 |
Updated Example_Instances, References |