Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-445 — Malicious Logic Insertion into Product Software via Configuration Management Manipulation
CAPEC-445

Malicious Logic Insertion into Product Software via Configuration Management Manipulation

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Medium. An adversary exploits a configuration management system so that malicious logic is inserted into a software products build, update or deployed environment. If an adversary can control the elements included in a product's configuration management for build they can potentially replace, modify or insert code files containing malicious logic. If an adversary can control elements of a product's ongoing operational configuration management baseline they can potentially force clients receiving updates from the system to install insecure software when receiving updates from the server.

Mitigation

Assess software during development and prior to deployment to ensure that it functions as intended and without any malicious functionality. | Leverage anti-virus products to detect and quarantine software with known virus.

Details

Platforms
Supply-chain
Software
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.