CAPEC-401: Physically Hacking Hardware
An adversary exploits a weakness in access control to gain access to currently installed hardware and precedes to implement changes or secretly replace a hardware component which undermines the system's integrity for the purpose of carrying out an attack.
Last updated
Overview
CAPEC-401 (Physically Hacking Hardware) is a standard-level attack pattern catalogued by MITRE in the Common Attack Pattern Enumeration and Classification (CAPEC). It describes a recurring method attackers use to exploit software weaknesses.
Examples
A malicious subcontractor or subcontractor's employee that is responsible for system maintenance secretly replaces a hard drive with one containing malicious code that will allow for backdoor access once deployed.
Frequently asked questions
Common questions about CAPEC-401.
- What is CAPEC-401?
- An adversary exploits a weakness in access control to gain access to currently installed hardware and precedes to implement changes or secretly replace a hardware component which undermines the system's integrity for the purpose of carrying out an attack.
- What weaknesses does CAPEC-401 target?
- CAPEC-401 exploits 1 CWE weakness, including CWE-1263 (Improper Physical Access Control).
- How severe is CAPEC-401?
- MITRE rates CAPEC-401 as High severity with low likelihood of attack.
References
Attack-pattern data is sourced from the MITRE CAPEC catalog (v3.9). Weakness associations link to the corresponding CWE entries on RadicalNotion.AI.
Defend against CAPEC-401
Track the CVEs and weaknesses attackers exploit with this technique, with AI-written analysis and remediation guidance.