Method confusion attack
Description
Method confusion attackRisk Assesment: 6.3
CWE
CVE
Attack Surfaces
Security Manager Protocol (MITRE EMB3D PID-4113)
Attack Vectors
Authentication skip (MITRE EMB3D TID-411)
Defenses
Enforce specific authentication method, Use OOB authentication
User interface fix, Display authentication method warning to the user
Authentication method validation, Embed information about the authentication method in the authentication data itself to make them distinguishable