Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-680 — Exploitation of Improperly Controlled Registers
CAPEC-680

Exploitation of Improperly Controlled Registers

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Medium. An adversary exploits missing or incorrectly configured access control within registers to read/write data that is not meant to be obtained or modified by a user.

Mitigation

Design proper access control policies for hardware register access from software and ensure these policies are implemented in accordance with the specified design. | Ensure security lock bit protections are reviewed for design inconsistencies and common weaknesses. | Test security lock programming flow in both pre-silicon and post-silicon environments. | Leverage automated tools to test that values are not reprogrammable and that write-once fields lock on writing zeros. | Ensure that measurement data is stored in registers that are read-only or otherwise have access controls that prevent modification by an untrusted agent.

Details

Platforms
Hardware
Hardware
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.