Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-22 — Exploiting Trust in Client
CAPEC-22

Exploiting Trust in Client

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: High. An attack of this type exploits vulnerabilities in client/server communication channel authentication and data integrity. It leverages the implicit trust a server places in the client, or more importantly, that which the server believes is the client. An attacker executes this type of attack by communicating directly with the server where the server believes it is communicating only with a valid client. There are numerous variations of this type of attack.

Mitigation

Design: Ensure that client process and/or message is authenticated so that anonymous communications and/or messages are not accepted by the system. | Design: Do not rely on client validation or encoding for security purposes. | Design: Utilize digital signatures to increase authentication assurance. | Design: Utilize two factor authentication to increase authentication assurance. | Implementation: Perform input validation for all remote content.

Details

Platforms
Communications
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.