CAPEC™ 115: Authentication Bypass
Description
An attacker gains access to application, service, or device with the privileges of an authorized or privileged user by evading or circumventing an authentication mechanism. The attacker is therefore able to access protected data without authentication ever having taken place.
Source: CAPEC™ 115
Related ASVS Requirements
ASVS (5.0): 10.1.1, 10.1.2, 10.2.1, 12.3.5, 13.2.1, 13.2.3, 15.2.4, 16.3.3, 16.5.3, 4.4.4, 6.1.1, 6.1.2, 6.1.3, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.4.2, 6.4.3, 6.4.4, 6.6.1, 6.7.1, 6.8.1, 6.8.2, 6.8.3, 6.8.4, 7.2.1, 7.5.1, 7.5.3, 8.4.2