CAPEC Definitions / CAPEC-519
CAPEC-519: Documentation Alteration to Cause Errors in System Design
An attacker with access to a manufacturer's documentation containing requirements allocation and software design processes maliciously alters the documentation in order to cause errors in system design. This allows the attacker to take advantage of a weakness in a deployed system of the manufacturer for malicious purposes.
Extended Description
No Extended Description.
Mitigations
Digitize documents and cryptographically sign them to verify authenticity.
Password protect documents and make them read-only for unauthorized users.
Avoid emailing important documents and configurations.
Ensure deleted files are actually deleted.
Maintain multiple instances of the document across different privileged users for recovery and verification.
Relationships with other CAPECs
CAPEC-447: Design Alteration
Prerequisites
Advanced knowledge of software capabilities of a manufacturer's product.
Access to the manufacturer's documentation.
Related Weaknesses
No related Weaknesses found.
