|
|
|
|
CWE-303: Incorrect Implementation of Authentication Algorithm
| | Incorrect Implementation of Authentication Algorithm |
|
| Weakness ID: 303 (Weakness Base) | | Status: Draft |
Description
Description Summary The requirements for the software dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
Extended Description This incorrect implementation may allow authentication to be bypassed.
Time of Introduction Common Consequences | Scope | Effect |
Access Control | Technical Impact: Bypass protection
mechanism |
Observed Examples | Reference | Description |
| CVE-2003-0750 | Conditional should have been an 'or' not an
'and'. |
Relationships | Nature | Type | ID | Name | View(s) this relationship pertains to |
| ChildOf | Weakness Class | 287 | Improper Authentication | Development Concepts (primary)699 Research Concepts (primary)1000 | | ChildOf | Category | 898 | SFP Cluster: Authentication | Software Fault Pattern (SFP) Clusters (primary)888 |
Taxonomy Mappings | Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
| PLOVER | | | Authentication Logic Error |
Content History | Submissions |
|---|
| Submission Date | Submitter | Organization | Source |
|---|
| PLOVER | | Externally Mined | | | Modifications |
|---|
| Modification Date | Modifier | Organization | Source |
|---|
| 2008-07-01 | Eric Dalci | Cigital | External | | updated Time_of_Introduction | | 2008-09-08 | CWE Content Team | MITRE | Internal | | updated Relationships,
Taxonomy_Mappings | | 2008-10-14 | CWE Content Team | MITRE | Internal | | updated Description | | 2009-05-27 | CWE Content Team | MITRE | Internal | | updated Description, Name | | 2011-06-01 | CWE Content Team | MITRE | Internal | | updated Common_Consequences | | 2012-05-11 | CWE Content Team | MITRE | Internal | | updated Relationships | | Previous Entry Names |
|---|
| Change Date | Previous Entry
Name |
|---|
| 2008-04-11 | Authentication Logic
Error | | | 2009-05-27 | Improper Implementation of
Authentication Algorithm | |
|