3. of Denial of Service I
An attacker can make a client unavailable or unusable but the problem goes away when the attacker stops (client, authenticated, temporary).
Threat |
|
You don’t support simultaneous sessions, or you have users who can remove connected devices that should no longer be used. An attacker is connecting with a legitimate user’s credentials and taking advantage of this to invalidate their session repeatedly. |
|
CAPEC |
CAPEC-74 – Manipulating state |
ASVS |
3.3.3 – Ensure a change of password terminates active sessions 3.3.5 – Ensure users can see and terminate an active session |
CWE |
CWE-1018 – Manage user sessions |