Skip to main content

Database / Vector

Threats

Version:
IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.Vector.TH01Embedding Extraction and Model InversionAttackers may infer or reconstruct original data by probing vector similarity APIs, especially with unrestricted access. This enables model inversion attacks, membership inference, and unauthorized data leakage from stored embeddings.
1
1
0
CCC.Vector.TH02Embedding and Index PoisoningAdversaries may insert malicious or adversarial vectors into the index through ingestion endpoints, polluting the dataset and degrading search quality, or subtly steering results toward specific outcomes.
1
1
3
CCC.Vector.TH03Cross-modal or Metadata LeakageAttackers may infer sensitive information through metadata filters or by correlating embeddings across modalities (e.g., voice and face), bypassing surface-level access controls.
1
1
1
CCC.Vector.TH04Index Corruption or DowngradeAttackers with unauthorized access or excessive permissions may tamper with or roll back index versions, potentially restoring poisoned data or breaking downstream integrations.
1
1
2
CCC.Vector.TH05Embedding Format or Dimension AttacksPoor validation of embedding formats or dimensions can cause service crashes or logic errors. This can result in denial of service or incorrect similarity results.
1
1
2
CCC.Vector.TH06Search Result Manipulation via ANN BiasApproximate nearest neighbor (ANN) algorithms may yield non-deterministic or biased results. Adversaries may exploit these differences to evade detection or bias AI responses.
2
1
1

Imports

IDRemarks
CCC.Core.TH01Access Control is Misconfigured
CCC.Core.TH02Data is Intercepted in Transit
CCC.Core.TH03Deployment Region Network is Untrusted
CCC.Core.TH04Data is Replicated to Untrusted or External Locations
CCC.Core.TH05Data is Corrupted During Replication
CCC.Core.TH06Data is Lost or Corrupted
CCC.Core.TH07Logs are Tampered With or Deleted
CCC.Core.TH08Cost Management Data is Manipulated
CCC.Core.TH09Logs or Monitoring Data are Read by Unauthorized Users
CCC.Core.TH10Alerts are Intercepted
CCC.Core.TH11Event Notifications are Incorrectly Triggered
CCC.Core.TH12Resource Constraints are Exhausted
CCC.Core.TH13Resource Tags are Manipulated
CCC.Core.TH14Older Resource Versions are Exploited
CCC.Core.TH15Automated Enumeration and Reconnaissance by Non-human Entities
CCC.Core.TH16Logging and Monitoring are Disabled
CCC.Core.TH17Unauthorized Network Access via Misconfigured Rules