BaseIncomplete
CWE-1270Generation of Incorrect Security Tokens
Category: auth
Description
The product implements a Security Token mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. However, the Security Tokens generated in the system are incorrect.
Common consequences· 1
- Confidentiality / Integrity / Availability / Access Control — Modify Files or Directories, Execute Unauthorized Code or Commands, Bypass Protection Mechanism, Gain Privileges or Assume Identity, Read Memory, Modify Memory, DoS: Crash, Exit, or RestartIncorrectly generated Security Tokens could result in the same token used for multiple agents or multiple tokens being used for the same agent. This condition could result in a Denial-of-Service (DoS) or the execution of an action that in turn could result in privilege escalation or unintended access.
Potential mitigations· 1
- [Architecture and Design, Implementation]
Related CAPEC attack patterns· 3
References
Exploits (incoming)3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Exploit Non-Production Interfacescapec-121 | 100% | live |
| AttackPattern | Exploitation of Improperly Controlled Hardware Security Identifierscapec-681 | 100% | live |
| AttackPattern | Token Impersonationcapec-633 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.