Insufficient data authenticity validation - Device Binding
Description
Insecure device pairing results in an insecure communication between two physical devices. Device-pairing protocols configured are vulnerable to the misbinding attacks, it arises from the lack of verifiable identifiers.
Impact
- Spoof, intercept and modify messages in the network in arbitrary ways. - Allow malicious behavior by one of the intended communication endpoints.
Recommendation
- Establish a shared cryptographic key between two or more communication endpoints to use the shared key for protecting communication integrity and confidentiality. - Specify security properties as correspondence assertions in addition to basic authentication properties, it can help to detect subtle flaws that might otherwise go unnoticed.
Threat
Attacker may impersonate one of the device communication endpoints or set itself as a man in the middle (MitM) between them.
Expected Remediation Time
⏱️ 300 minutes.
Requirements
122 - Validate credential ownership173 - Discard unsafe inputs178 - Use digital signatures320 - Avoid client-side control enforcementFixes
Score
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
Attack vector
N
Attack complexity
L
Attack requirements
N
Privileges required
N
User interaction
N
Confidentiality (VC)
L
Integrity (VI)
L
Availability (VA)
N
Confidentiality (SC)
N
Integrity (SI)
N
Availability (SA)
N
Threat 4.0
Exploit maturity
X
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N