CWE-419

Unprotected Primary Channel

Weakness Description

The product uses a primary channel for administration or restricted functionality, but it does not properly protect the channel.

Potential Mitigations

Architecture and Design

Do not expose administrative functionnality on the user UI.

Architecture and Design

Protect the administrative/restricted functionality with a strong authentication mechanism.

Common Consequences

Access Control
Gain Privileges or Assume IdentityBypass Protection Mechanism
Advertisement

Related Weaknesses