CWE-420

Unprotected Alternate Channel
AI Translation Available

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Status
draft
Abstraction
base

Common Consequences

access control
Impacts
gain privileges or assume identity bypass protection mechanism

Potential Mitigations

Phases:
architecture and design
Descriptions:
• Identify all alternate channels and use the same protection mechanisms that are used for the primary channels.