CAPEC Definitions / CAPEC-121
CAPEC-121: Exploit Non-Production Interfaces
An adversary exploits a sample, demonstration, test, or debug interface that is unintentionally enabled on a production system, with the goal of gleaning information or leveraging functionality that would otherwise be unavailable.
Extended Description
Non-production interfaces are insecure by default and should not be resident on production systems, since they may reveal sensitive information or functionality that should not be known to end-users. However, such interfaces may be unintentionally left enabled on a production system due to configuration errors, supply chain mismanagement, or other pre-deployment activities. Ultimately, failure to properly disable non-production interfaces, in a production environment, may expose a great deal of diagnostic information or functionality to an adversary, which can be utilized to further refine their attack. Moreover, many non-production interfaces do not have adequate security controls or may not have undergone rigorous testing since they were not intended for use in production environments. As such, they may contain many flaws and vulnerabilities that could allow an adversary to severely disrupt a target.
Mitigations
Ensure that production systems do not contain non-production interfaces and that these interfaces are only used in development environments.
Relationships with other CAPECs
CAPEC-113: Interface Manipulation
Prerequisites
The target must have configured non-production interfaces and failed to secure or remove them when brought into a production environment.
Related Weaknesses
CWE-489: Active Debug Code
CWE-1209: Failure to Disable Reserved Bits
CWE-1259: Improper Restriction of Security Token Assignment
CWE-1267: Policy Uses Obsolete Encoding
CWE-1270: Generation of Incorrect Security Tokens
CWE-1294: Insecure Security Identifier Mechanism
CWE-1295: Debug Messages Revealing Unnecessary Information
CWE-1296: Incorrect Chaining or Granularity of Debug Components
CWE-1302: Missing Source Identifier in Entity Transactions on a System-On-Chip (SOC)
CWE-1313: Hardware Allows Activation of Test or Debug Logic at Runtime
