Umbra Wiki weakness weakness/CWE-654
Back to wiki

CWE-654 — Reliance on a Single Factor in a Security Decision

provenance: imported · CWE: CWE-654

CWE-654: Reliance on a Single Factor in a Security Decision

MITRE CWE weakness

Kind Weakness
Abstraction Base
Status Draft
Likelihood of exploit

Description

A protection mechanism relies exclusively, or to a large extent, on the evaluation of a single condition or the integrity of a single object or entity in order to make a decision about granting access to restricted resources or functionality.

Common consequences

  • Access Control: Gain Privileges or Assume Identity
  • Non-Repudiation: Hide Activities

Mitigations

Architecture and Design — Use multiple simultaneous checks before granting access to critical operations or granting critical privileges. A weaker but helpful mitigation is to use several successive checks (multiple layers of security).

Architecture and Design — Use redundant access rules on different choke points (e.g., firewalls).

References

  • CWE page: https://cwe.mitre.org/data/definitions/654.html
  • CWE list: https://cwe.mitre.org/data/index.html