Umbra Wiki weakness weakness/CWE-424
Back to wiki

CWE-424 — Improper Protection of Alternate Path

provenance: imported · CWE: CWE-424

CWE-424: Improper Protection of Alternate Path

MITRE CWE weakness

Kind Weakness
Abstraction Class
Status Draft
Likelihood of exploit

Description

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.

Common consequences

  • Access Control: Bypass Protection Mechanism, Gain Privileges or Assume Identity

Mitigations

Architecture and Design — Deploy different layers of protection to implement security in depth.

References

  • CWE page: https://cwe.mitre.org/data/definitions/424.html
  • CWE list: https://cwe.mitre.org/data/index.html