CAPEC Definitions

    CAPEC Definitions / CAPEC-530

    CAPEC-530: Provide Counterfeit Component

    An attacker provides a counterfeit component during the procurement process of a lower-tier component supplier to a sub-system developer or integrator, which is then built into the system being upgraded or repaired by the victim, allowing the attacker to cause disruption or additional compromise.

    Severity:High
    Possibility:Low

    Extended Description

    No Extended Description.

    Mitigations

    There are various methods to detect if the component is a counterfeit. See section II of [REF-703] for many techniques.

    Relationships with other CAPECs

    CAPEC-531: Hardware Component Substitution

    Prerequisites

    Advanced knowledge about the target system and sub-components.

    Related Weaknesses

    No related Weaknesses found.