CWE-420: Unprotected Alternate Channel

What is CWE-420?

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Analyzing data...

Data statistics

RELATED CVES (365 DAYS)6
ABSTRACTIONBase

Vulnerabilities mapped to CWE-420

6 vulnerabilities100% increase year over year

Vulnerabilities in CISA KEV for CWE-420

0 vulnerabilities

Official definition

ByMitre CWE

The product protects a primary channel, but it does not use the same level of protection for an alternate channel.

Characteristics

Modes of introduction

  • Architecture and Design: OMISSION: This weakness is caused by missing a security tactic during the architecture and design phase.
  • Implementation
  • Operation

Common consequences

ImpactScopeExplanation
Gain Privileges or Assume Identity, Bypass Protection MechanismAccess Control—

Risk mitigations

  1. Architecture and DesignIdentify all alternate channels and use the same protection mechanisms that are used for the primary channels.

Representative vulnerabilities

Sources (2)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan