ClassIncomplete
CWE-923Improper Restriction of Communication Channel to Intended Endpoints
Category: other
Description
The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
Common consequences· 1
- Integrity / Confidentiality — Gain Privileges or Assume IdentityIf an attacker can spoof the endpoint, the attacker gains all the privileges that were intended for the original endpoint.
Related CAPEC attack patterns· 4
References
Exploits (incoming)4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| AttackPattern | Infrastructure Manipulationcapec-161 | 100% | live |
| AttackPattern | DHCP Spoofingcapec-697 | 100% | live |
| AttackPattern | Contradictory Destinations in Traffic Routing Schemescapec-481 | 100% | live |
| AttackPattern | Android Activity Hijackcapec-501 | 100% | live |
(incoming)6
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Vulnerability | CVE-2025-20261cve-2025-20261 | 0% | live |
| Vulnerability | CVE-2025-29986cve-2025-29986 | 0% | live |
| Vulnerability | CVE-2025-46566cve-2025-46566 | 0% | live |
| Vulnerability | CVE-2025-48999cve-2025-48999 | 0% | live |
| Vulnerability | CVE-2026-34205cve-2026-34205 | 0% | live |
| KEVEntry | Cisco IOS XR Open Port Vulnerabilitykev-cve-2022-20821 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.