Umbra Wiki weakness weakness/CWE-303
Back to wiki

CWE-303 — Incorrect Implementation of Authentication Algorithm

provenance: imported · CWE: CWE-303

CWE-303: Incorrect Implementation of Authentication Algorithm

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Draft
Likelihood of exploit

Description

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

This incorrect implementation may allow authentication to be bypassed.

Common consequences

  • Access Control: Bypass Protection Mechanism

Mitigations

(none listed)

References

  • CWE page: https://cwe.mitre.org/data/definitions/303.html
  • CWE list: https://cwe.mitre.org/data/index.html