CWE-291

Overview
  • CWE ID
  • 291
  • CWE Name
  • Reliance on IP Address for Authentication
  • CWE Abstraction
  • Variant
  • CWE structure
  • Simple
  • CWE Status
  • Incomplete
Description
The software uses an IP address for authentication.
Extended Description
IP addresses can be easily spoofed. Attackers can forge the source IP address of the packets they send, but response packets will return to the forged IP address. To see the response packets, the attacker has to sniff the traffic between the victim machin
Related CWEs
CWE ID View ID Nature Ordinal
290 1000 ChildOf Primary
923 1000 ChildOf
471 1000 ChildOf