Compliance Node Overview
MITRE CAPEC-180 (Exploiting Incorrectly Configured Access Control Security Levels) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker exploits a weakness in the configuration of access controls and is able to bypass the intended protection that these measures guard against and thereby obtain unauthorized access to the system or network. Sensitive functionality should always be protected with access controls. Likelihood of attack: High. Typical severity: Medium. Parent pattern for CAPEC-58 Restful Privilege Elevation; CAPEC-679 Exploitation of Improperly Configured or Implemented Memory Protections; CAPEC-680 Exploitation of Improperly Controlled Registers; and others. Maps to weaknesses CWE-732, CWE-1190, CWE-1191, CWE-1193, and others. Relates to MITRE ATT&CK T1574.010.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/180.html
SHA-256 integrity: e3eb42876cf9ed2815f1a550ea243e0eb3a31ffb3e5d4a2d414e79b8979b3293
Primary Citations — 13 traced to source
- MITRE CAPEC-180: Exploiting Incorrectly Configured Access Control Security Levels (https://capec.mitre.org/data/definitions/180.html)
- CWE-732: underlying weakness (http://cwe.mitre.org/data/definitions/732.html)
+ 11 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.