Typical severity: Very High. Likelihood of attack: High. An adversary targets the communication between two components (typically client and server), in order to alter or obtain data from transactions. A general approach entails the adversary placing themself within the communication channel between the two components.
Ensure Public Keys are signed by a Certificate Authority | Encrypt communications using cryptography (e.g., SSL/TLS) | Use Strong mutual authentication to always fully authenticate both ends of any communications channel. | Exchange public keys using a secure channel