CWE-603: Use of Client-Side Authentication

ID CWE-603
Abstraction Base
Structure Simple
Status Draft
Number of CVEs 9
A client/server product performs authentication within client code but not in server code, allowing server-side authentication to be bypassed via a modified client that omits the authentication check.

Client-side authentication is extremely weak and may be breached easily. Any attacker may read the source code and reverse-engineer the authentication mechanism to access parts of the application which would otherwise be protected.

Modes of Introduction

Phase Note
Architecture and Design COMMISSION: This weakness refers to an incorrect design related to an architectural security tactic.

Applicable Platforms

Type Class Name Prevalence
Language Not Language-Specific
Technology ICS/OT


View Weakness
# ID View Status # ID Name Abstraction Structure Status
CWE-1000 Research Concepts Draft CWE-1390 Weak Authentication Class Simple Incomplete
CWE-1000 Research Concepts Draft CWE-602 Client-Side Enforcement of Server-Side Security Class Simple Draft
CWE-1000 Research Concepts Draft CWE-300 Channel Accessible by Non-Endpoint Class Simple Draft
CWE-1000 Research Concepts Draft CWE-656 Reliance on Security Through Obscurity Class Simple Draft

CVEs Published

CVSS Severity

CVSS Severity - By Year

CVSS Base Score

# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date