BaseDraft
CWE-372Incomplete Internal State Distinction
Category: other
Description
The product does not properly determine which state it is in, causing it to assume it is in state X when in fact it is in state Y, causing it to perform incorrect operations in a security-relevant manner.
Common consequences· 1
- Integrity / Other — Varies by Context, Unexpected State
Related CAPEC attack patterns· 2
References
Exploits (incoming)2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Bypassing of Intermediate Forms in Multiple-Form Setscapec-140 | 100% | live |
| AttackPattern | Manipulating Statecapec-74 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.