|
|
|
|
CWE-419: Unprotected Primary Channel
| | Unprotected Primary Channel |
|
| Weakness ID: 419 (Weakness Base) | | Status: Draft |
Description
Description Summary The software uses a primary channel for administration or restricted functionality, but it does not properly protect the channel.
Time of Introduction
- Architecture and Design
- Implementation
Common Consequences | Scope | Effect |
Access Control | Technical Impact: Gain privileges / assume
identity; Bypass protection
mechanism |
Potential Mitigations
Do not expose administrative functionnality on the user UI. |
Protect the administrative/restricted functionallities with strong
authentication mechanism. |
Relationships Taxonomy Mappings | Mapped Taxonomy Name | Node ID | Fit | Mapped Node Name |
| PLOVER | | | Unprotected Primary Channel |
Content History | Submissions |
|---|
| Submission Date | Submitter | Organization | Source |
|---|
| PLOVER | | Externally Mined | | | Modifications |
|---|
| Modification Date | Modifier | Organization | Source |
|---|
| 2008-07-01 | Eric Dalci | Cigital | External | | updated Potential_Mitigations,
Time_of_Introduction | | 2008-09-08 | CWE Content Team | MITRE | Internal | | updated Relationships,
Taxonomy_Mappings | | 2010-12-13 | CWE Content Team | MITRE | Internal | | updated Related_Attack_Patterns | | 2011-06-01 | CWE Content Team | MITRE | Internal | | updated Common_Consequences |
|