Umbra Wiki weakness weakness/CWE-348
Back to wiki

CWE-348 — Use of Less Trusted Source

provenance: imported · CWE: CWE-348

CWE-348: Use of Less Trusted Source

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Draft
Likelihood of exploit

Description

The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

Common consequences

  • Access Control: Bypass Protection Mechanism, Gain Privileges or Assume Identity

Mitigations

(none listed)

References

  • CWE page: https://cwe.mitre.org/data/definitions/348.html
  • CWE list: https://cwe.mitre.org/data/index.html