What MITRE CAPEC-2: Inducing Account Lockout (Standard Attack Pattern - Medium Severity) requires
MITRE CAPEC-2 (Inducing Account Lockout) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An attacker leverages the security functionality of the system aimed at thwarting potential attacks to launch a denial of service attack against a legitimate system user. Many systems, for instance, implement a password throttling mechanism that locks an account after a certain number of incorrect log in attempts. An attacker can leverage this throttling mechanism to lock a legitimate user out of their own account. Likelihood of attack: High. Typical severity: Medium. Maps to weaknesses CWE-645. Relates to MITRE ATT&CK T1531.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/2.html
SHA-256 integrity: d0414abde14f563583f6684c23aaf2cd15f65d9ef1e5de1ba7430b491364c094
Primary Citations — 8 traced to source
- MITRE CAPEC-2: Inducing Account Lockout (https://capec.mitre.org/data/definitions/2.html)
- CWE-645: underlying weakness (http://cwe.mitre.org/data/definitions/645.html)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.