CWE

Common Weakness Enumeration

A Community-Developed Dictionary of Software Weakness Types

CWE/SANS Top 25 Most Dangerous Software Errors Common Weakness Scoring System
Common Weakness Risk Analysis Framework
Home > CWE List > CWE- Individual Dictionary Definition (2.6)  

Presentation Filter:

CWE-417: Channel and Path Errors

 
Channel and Path Errors
Category ID: 417 (Category)Status: Draft
+ Description

Description Summary

Weaknesses in this category are related to improper handling of communication channels and access paths.
+ Applicable Platforms

Languages

All

+ Relationships
NatureTypeIDNameView(s) this relationship pertains toView(s)
ChildOfCategoryCategory18Source Code
Development Concepts (primary)699
ChildOfCategoryCategory399Resource Management Errors
Development Concepts699
ParentOfCategoryCategory418Channel Errors
Development Concepts (primary)699
ParentOfWeakness ClassWeakness Class424Improper Protection of Alternate Path
Development Concepts (primary)699
ParentOfCompound Element: CompositeCompound Element: Composite426Untrusted Search Path
Development Concepts (primary)699
ParentOfWeakness BaseWeakness Base427Uncontrolled Search Path Element
Development Concepts (primary)699
ParentOfWeakness BaseWeakness Base428Unquoted Search Path or Element
Development Concepts (primary)699
+ Relationship Notes

A number of vulnerabilities are specifically related to problems in creating, managing, or removing alternate channels and alternate paths. Some of these can overlap virtual file problems. They are commonly used in "bypass" attacks, such as those that exploit authentication errors.

+ Research Gaps

Most of these issues are probably under-studied. Only a handful of public reports exist.

+ Taxonomy Mappings
Mapped Taxonomy NameNode IDFitMapped Node Name
PLOVERCHAP.VIRTFILEChannel and Path Errors
+ Content History
Submissions
Submission DateSubmitterOrganizationSource
PLOVERExternally Mined
Modifications
Modification DateModifierOrganizationSource
2008-09-08CWE Content TeamMITREInternal
updated Relationships, Other_Notes, Taxonomy_Mappings
2009-07-27CWE Content TeamMITREInternal
updated Other_Notes, Relationship_Notes
Page Last Updated: February 18, 2014