CWE-592: Authentication Bypass Issues
Authentication Bypass Issues
Weakness ID: 592 (Weakness Class) Status: Incomplete
Description
Description Summary
The software does not properly perform authentication , allowing it to be bypassed through various methods.
Time of Introduction
Architecture and Design
Implementation
Operation
Common Consequences
Scope Effect
Access Control
Technical Impact: Bypass protection
mechanism; Gain privileges / assume
identity
Relationships
Taxonomy Mappings
Mapped Taxonomy Name Node ID Fit Mapped Node Name
OWASP Top Ten 2004 A3 CWE_More_Specific Broken Authentication and Session
Management
References
[REF-7] Mark Dowd, John McDonald
and Justin Schuh. "The Art of Software Security Assessment". Chapter 2, "Untrustworthy Credentials", Page
37.. 1st Edition. Addison Wesley. 2006.
Content History
Modifications Modification Date Modifier Organization Source 2008-07-01 Eric Dalci Cigital External updated Time_of_Introduction 2008-09-08 CWE Content Team MITRE Internal updated Relationships,
Taxonomy_Mappings 2009-05-27 CWE Content Team MITRE Internal updated Related_Attack_Patterns 2011-06-01 CWE Content Team MITRE Internal updated Common_Consequences 2012-05-11 CWE Content Team MITRE Internal updated References, Relationships