CWE-300

Overview
  • CWE ID
  • 300
  • CWE Name
  • Channel Accessible by Non-Endpoint
  • CWE Abstraction
  • Class
  • CWE structure
  • Simple
  • CWE Status
  • Draft
Description
The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an end
Extended Description
In order to establish secure communication between two parties, it is often important to adequately verify the identity of entities at each end of the communication channel. Inadequate or inconsistent verification may result in insufficient or incorrect i
Related CWEs
CWE ID View ID Nature Ordinal
923 1000 ChildOf Primary