CAPEC™ 114: Authentication Abuse
Description
An attacker obtains unauthorized access to an application, service or device either through knowledge of the inherent weaknesses of an authentication mechanism, or by exploiting a flaw in the authentication scheme's implementation. In such an attack an authentication mechanism is functioning but a carefully controlled sequence of events causes the mechanism to grant access to the attacker.
Source: CAPEC™ 114
Related ASVS Requirements
ASVS (5.0): 11.2.1, 11.2.3, 11.2.4, 11.2.5, 11.3.1, 11.3.2, 11.3.3, 11.3.4, 11.3.5, 11.4.1, 11.4.3, 11.5.1, 11.5.2, 11.6.1, 11.6.2, 16.3.1, 16.3.2, 16.3.3, 16.3.4, 16.5.2, 16.5.3, 6.1.1, 6.1.2, 6.1.3, 6.2.3, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.2, 6.4.3, 6.4.4, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.7.1, 6.7.2, 6.8.1, 6.8.2, 6.8.3, 6.8.4, 7.5.1, 7.5.3, 8.1.3, 8.1.4, 8.4.2