CWE-654 — Reliance on a Single Factor in a Security Decision
CWE-654: Reliance on a Single Factor in a Security Decision
MITRE CWE weakness
| Kind | Weakness |
| Abstraction | Base |
| Status | Draft |
| Likelihood of exploit | — |
Description
A protection mechanism relies exclusively, or to a large extent, on the evaluation of a single condition or the integrity of a single object or entity in order to make a decision about granting access to restricted resources or functionality.
Common consequences
- Access Control: Gain Privileges or Assume Identity
- Non-Repudiation: Hide Activities
Mitigations
Architecture and Design — Use multiple simultaneous checks before granting access to critical operations or granting critical privileges. A weaker but helpful mitigation is to use several successive checks (multiple layers of security).
Architecture and Design — Use redundant access rules on different choke points (e.g., firewalls).
References
- CWE page: https://cwe.mitre.org/data/definitions/654.html
- CWE list: https://cwe.mitre.org/data/index.html