BaseDraft
CWE-419Unprotected Primary Channel
Category: other
Description
The product uses a primary channel for administration or restricted functionality, but it does not properly protect the channel.
Common consequences· 1
- Access Control — Gain Privileges or Assume Identity, Bypass Protection Mechanism
Potential mitigations· 2
- [Architecture and Design]Do not expose administrative functionnality on the user UI.
- [Architecture and Design]Protect the administrative/restricted functionality with a strong authentication mechanism.
Related CAPEC attack patterns· 1
References
Exploits (incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Harvesting Information via API Event Monitoringcapec-383 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.