3. of Elevation of Privilege (2022 deck) II
An attacker can access the cloud service which manages your devices.
Threat |
|
Your cloud console admin account isn’t secure, so an attacker can spin up new instances for crypto mining, which are charged back to you. |
|
CAPEC |
CAPEC-1 – Accessing functionality not properly constrained by ACLs CAPEC-565 – Password spraying CAPEC-180 – Exploiting incorrectly configured access control security levels |
ASVS |
4.3.1 – Ensure usage of MFA |
CWE |
CWE-1220 – Insufficient granularity of access control |
Mitigations |
|
|