CWE-420
Unprotected Alternate Channel
AI Translation Available
The product protects a primary channel, but it does not use the same level of protection for an alternate channel.
Status
draft
Abstraction
base
Affected Platforms
Technical Details
AI Translation
Common Consequences
access control
Impacts
gain privileges or assume identity
bypass protection mechanism
Potential Mitigations
Phases:
architecture and design
Descriptions:
•
Identify all alternate channels and use the same protection mechanisms that are used for the primary channels.