CAPEC Definitions
CAPEC Definitions / CAPEC-530
CAPEC-530: Provide Counterfeit Component
An attacker provides a counterfeit component during the procurement process of a lower-tier component supplier to a sub-system developer or integrator, which is then built into the system being upgraded or repaired by the victim, allowing the attacker to cause disruption or additional compromise.
Severity:High
Possibility:Low
Extended Description
No Extended Description.
Mitigations
There are various methods to detect if the component is a counterfeit. See section II of [REF-703] for many techniques.
Relationships with other CAPECs
CAPEC-531: Hardware Component Substitution
Prerequisites
Advanced knowledge about the target system and sub-components.
Related Weaknesses
No related Weaknesses found.
