Compliance Node Overview
MITRE CAPEC-40 (Manipulating Writeable Terminal Devices) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack exploits terminal devices that allow themselves to be written to by other users. The attacker sends command strings to the target terminal device hoping that the target user will hit enter and thereby execute the malicious command with their privileges. The attacker can send the results (such as copying /etc/passwd) to a known directory and collect once the attack has succeeded. Likelihood of attack: High. Typical severity: Very High. Maps to weaknesses CWE-77.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/40.html
SHA-256 integrity: 80883de78142bc5e064d3e6662e8eb686046e9a9af3ed12eea8508c907c57b40
Primary Citations — 7 traced to source
- MITRE CAPEC-40: Manipulating Writeable Terminal Devices (https://capec.mitre.org/data/definitions/40.html)
- CWE-77: underlying weakness (http://cwe.mitre.org/data/definitions/77.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.