risk
Communications interception, eavesdropping and man-in-the-middle
Passive monitoring/sniffing of communications, interception of unencrypted or weakly encrypted channels, wireless interception, and man-in-the-middle attacks capture or corrupt transmitted data — including TEMPEST-type emanation capture.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Network & Communications Security
- Cryptography & Key Management
- Data Protection & Privacy
- taxonomy
- iso-27005-threat
- nist-800-30-threat-event
- iso-27005-vulnerability
- inherent_rating
- high
Details
- risk_id
- net-interception-mitm
- category
- cyber_security
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-threat
- nist-800-30-threat-event
- iso-27005-vulnerability
Source
No record-specific source URL is provided.
Connections
- UC-NET-07 — Secure name resolution and time services mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- related
- rationale
- Authenticated, integrity-verified name resolution prevents DNS spoofing/redirection that enables man-in-the-middle.
- UC-NET-03 — Provide trusted channels and control session lifecycle mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- primary
- rationale
- Trusted, mutually authenticated communication paths plus session-integrity protection prevent man-in-the-middle interception and insertion.
- UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- related
- rationale
- Banning early TLS and weak ciphers prevents protocol-downgrade and decryption of captured traffic, hardening the in-transit encryption that blocks interception.
- UC-CRYPTO-04 — Protect data in use from unauthorized access mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- related
- rationale
- session/memory protection reduces exposure of data held in active communication sessions
- UC-NET-02 — Authorize and secure remote, wireless, and mobile access mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- primary
- rationale
- Encryption, wireless link-level protection, and mutual authentication defeat eavesdropping, wireless interception, and man-in-the-middle on these links.
- UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- related
- rationale
- Protecting private keys in HSMs and revoking compromised certs denies attackers the stolen-key/impersonation path used for eavesdropping and man-in-the-middle.
- UC-CRYPTO-01 — Encrypt data at rest and in transit mitigates Communications interception, eavesdropping and man-in-the-middle
- strength
- primary
- rationale
- Strong in-transit encryption defeats passive sniffing/eavesdropping while trusted certificates and no-insecure-fallback block man-in-the-middle on public networks.