CAPEC Definitions

    CAPEC Definitions / CAPEC-678

    CAPEC-678: System Build Data Maliciously Altered

    During the system build process, the system is deliberately misconfigured by the alteration of the build data. Access to system configuration data files and build processes is susceptible to deliberate misconfiguration of the system.

    Severity:High
    Possibility:Low

    Extended Description

    No Extended Description.

    Mitigations

    Implement configuration management security practices that protect the integrity of software and associated data.

    Monitor and control access to the configuration management system.

    Harden centralized repositories against attack.

    Establish acceptance criteria for configuration management check-in to assure integrity.

    Plan for and audit the security of configuration management administration processes.

    Maintain configuration control over operational systems.

    Relationships with other CAPECs

    CAPEC-444: Development Alteration

    Prerequisites

    An adversary has access to the data files and processes used for executing system configuration and performing the build.

    Related Weaknesses

    No related Weaknesses found.

    CAPEC-678: System Build Data Maliciously Altered | CVE-DB