CWE-1413: Comprehensive Categorization: Protection Mechanism Failure

ID CWE-1413
Status Incomplete
Weaknesses in this category are related to protection mechanism failure.


View Weakness
# ID Name # ID Name Abstraction Structure Status
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-182 Collapse of Data into Unsafe Value Base Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-184 Incomplete List of Disallowed Inputs Base Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-222 Truncation of Security-relevant Information Base Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-223 Omission of Security-relevant Information Base Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-224 Obscured Security-relevant Information by Alternate Name Base Simple Incomplete
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-356 Product UI does not Warn User of Unsafe Actions Base Simple Incomplete
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-357 Insufficient UI Warning of Dangerous Operations Base Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-450 Multiple Interpretations of UI Input Base Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-602 Client-Side Enforcement of Server-Side Security Class Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-693 Protection Mechanism Failure Pillar Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') Base Simple Incomplete
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-778 Insufficient Logging Base Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-807 Reliance on Untrusted Inputs in a Security Decision Base Simple Incomplete
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-1039 Automated Recognition Mechanism with Inadequate Detection or Handling of Adversarial Input Perturbations Class Simple Incomplete
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-1248 Semiconductor Defects in Hardware Logic with Security-Sensitive Implications Base Simple Incomplete
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-1253 Incorrect Selection of Fuse Values Base Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-1269 Product Released in Non-Release Configuration Base Simple Incomplete
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-1278 Missing Protection Against Hardware Reverse Engineering Using Integrated Circuit (IC) Imaging Techniques Base Simple Incomplete
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-1291 Public Key Re-Use for Signing both Debug and Production Code Base Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-1318 Missing Support for Security Features in On-chip Fabrics or Buses Base Simple Incomplete
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-1319 Improper Protection against Electromagnetic Fault Injection (EM-FI) Base Simple Incomplete
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-1326 Missing Immutable Root of Trust in Hardware Base Simple Draft
CWE-1400 Comprehensive Categorization for Software Assurance Trends CWE-1338 Improper Protections Against Hardware Overheating Base Simple Draft