CWE-642
External Control of Critical State Data
ClassDraftLikelihood: High
Description
The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-21 · CAPEC-31
CVEs mapped to this weakness (21)
page 2 of 2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-58265 | Low | 0.13 | 3.1 | 0.00 | Jul 27, 2025 | The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery. |
- risk 0.13cvss 3.1epss 0.00
The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a nonce and thereby denying message delivery.