BaseIncomplete

CWE-940Improper Verification of Source of a Communication Channel

Category: other

Description

The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin. When an attacker can successfully establish a communication channel from an untrusted origin, the attacker may be able to gain privileges and access unexpected functionality.

Common consequences· 1

  • Access Control / Other — Gain Privileges or Assume Identity, Varies by Context, Bypass Protection Mechanism
    An attacker can access any functionality that is inadvertently accessible to the source.

Potential mitigations· 1

  • [Architecture and Design]

Related CAPEC attack patterns· 4

CAPEC-500CAPEC-594CAPEC-595CAPEC-596

References

  1. https://cwe.mitre.org/data/definitions/940.html

Exploits (incoming)4

TypeTargetConfidenceTier
AttackPatternTraffic Injectioncapec-594100%live
AttackPatternWebView Injectioncapec-500100%live
AttackPatternConnection Resetcapec-595100%live
AttackPatternTCP RST Injectioncapec-596100%live

(incoming)8

TypeTargetConfidenceTier
VulnerabilityCVE-2025-23222cve-2025-232220%live
VulnerabilityCVE-2025-59159cve-2025-591590%live
VulnerabilityMotex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerabilitycve-2025-619320%live
VulnerabilityCVE-2026-33875cve-2026-338750%live
VulnerabilityCVE-2026-35643cve-2026-356430%live
VulnerabilityCVE-2026-40434cve-2026-404340%live
KEVEntryPalo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerabilitykev-cve-2022-00280%live
KEVEntryMotex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerabilitykev-cve-2025-619320%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Improper Restriction of Communication Channel to Intended Endpoints
CWE
Channel Accessible by Non-Endpoint
CWE
Improper Enforcement of Message Integrity During Transmission in a Communication Channel
CWE
Improper Access Control
CWE
Missing Origin Validation in WebSockets
CWE
Insufficiently Protected Credentials
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.