Malicious Logic Insertion into Product via Inclusion of Third-Party Component
CAPEC-446 · Detailed · Stable
An adversary conducts supply chain attacks by the inclusion of insecure third-party components into a technology, product, or code-base, possibly packaging a malicious driver or component along with the product before shipping it to the consumer or acquirer.
likelihood: Medium
severity: High