ClassDraft

CWE-610Externally Controlled Reference to a Resource in Another Sphere

Category: logic

Description

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Common consequences· 2

  • Confidentiality / Integrity — Read Application Data, Modify Application Data
    An adversary could read or modify data, depending on how the resource is intended to be used.
  • Access Control — Gain Privileges or Assume Identity
    An adversary that can supply a reference to an unintended resource can potentially access a resource that they do not have privileges for, thus bypassing existing access control mechanisms.

Related CAPEC attack patterns· 1

CAPEC-219

References

  1. https://cwe.mitre.org/data/definitions/610.html

Exploits (incoming)1

TypeTargetConfidenceTier
AttackPatternXML Routing Detour Attackscapec-219100%live

Compliance frameworks addressing this (incoming)1

TypeTargetConfidenceTier
ComplianceControlowasp_top10-a10100%live

(incoming)24

TypeTargetConfidenceTier
VulnerabilityPalo Alto Networks PAN-OS File Read Vulnerabilitycve-2025-01110%live
VulnerabilityCVE-2025-10091cve-2025-100910%live
VulnerabilityCVE-2025-10092cve-2025-100920%live
VulnerabilityCVE-2025-10816cve-2025-108160%live
VulnerabilityCVE-2025-11035cve-2025-110350%live
VulnerabilityCVE-2025-11140cve-2025-111400%live
VulnerabilityCVE-2025-11341cve-2025-113410%live
VulnerabilityCVE-2025-22144cve-2025-221440%live
VulnerabilityCVE-2025-3241cve-2025-32410%live
VulnerabilityCVE-2025-5877cve-2025-58770%live
VulnerabilityCVE-2025-6691cve-2025-66910%live
VulnerabilityCVE-2025-7523cve-2025-75230%live
VulnerabilityCVE-2025-7823cve-2025-78230%live
VulnerabilityCVE-2025-7824cve-2025-78240%live
VulnerabilityCVE-2025-9065cve-2025-90650%live
VulnerabilityCVE-2026-0522cve-2026-05220%live
VulnerabilityCVE-2026-30903cve-2026-309030%live
VulnerabilityCVE-2026-3404cve-2026-34040%live
VulnerabilityCVE-2026-34327cve-2026-343270%live
VulnerabilityCVE-2026-45760cve-2026-457600%live
VulnerabilityCVE-2026-47357cve-2026-473570%live
VulnerabilityCVE-2026-47358cve-2026-473580%live
KEVEntryQNAP Photo Station Externally Controlled Reference Vulnerabilitykev-cve-2022-275930%live
KEVEntryMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerabilitykev-cve-2022-301900%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Use of Incorrectly-Resolved Name or Reference
CWE
Exposure of Resource to Wrong Sphere
CWE
Inclusion of Functionality from Untrusted Control Sphere
CWE
Incorrect Ownership Assignment
CWE
Improper Control of Resource Identifiers ('Resource Injection')
CWE
External Influence of Sphere Definition
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.