Pré-requisitos
An authoritative or reputable signer is storing their private signature key with insufficient protection.
Habilidades Necessárias
Knowledge of common location methods and access methods to sensitive data
Ability to compromise systems containing sensitive data
Mitigações
Restrict access to private keys from non-supervisory accounts
Restrict access to administrative personnel and processes only
Ensure all remote methods are secured
Ensure all services are patched and up to date
Fraquezas Relacionadas
| CWE-ID |
Nome da Fraqueza |
|
Insufficiently Protected Credentials The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |
Referências
REF-411
Security breach stopped
Sigbjørn Vik.
REF-412
Bit9 and Our Customers’ Security
Patrick Morley.
REF-413
Inappropriate Use of Adobe Code Signing Certificate
Brad Arkin.
Submissão
| Nome |
Organização |
Data |
Data de lançamento |
| CAPEC Content Team |
The MITRE Corporation |
2014-06-23 +00:00 |
|
Modificações
| Nome |
Organização |
Data |
Comentário |
| CAPEC Content Team |
The MITRE Corporation |
2019-04-04 +00:00 |
Updated Related_Weaknesses |
| CAPEC Content Team |
The MITRE Corporation |
2020-12-17 +00:00 |
Updated Mitigations |
| CAPEC Content Team |
The MITRE Corporation |
2022-09-29 +00:00 |
Updated Taxonomy_Mappings |