3. of Elevation of Privilege (2022 deck) I
An attacker can access the cloud service that manages your devices.
Threat |
|
Your burglar alarm and video surveillance are connected to the cloud but the cloud you are using isn’t securely configured, so a bad actor can connect and watch when you are at home from a remote location and disable your alarm so that they can break in. |
|
CAPEC |
CAPEC-1 – Accessing functionality not properly constrained by ACLs CAPEC-565 – Password spraying CAPEC-180 – Exploiting incorrectly configured access control security levels |
ASVS |
4.3.1 – Ensure usage of MFA |
CWE |
CWE-1220 – Insufficient granularity of access control |