VYPR

CWE-654

Reliance on a Single Factor in a Security Decision

BaseDraft

Description

A protection mechanism relies exclusively, or to a large extent, on the evaluation of a single condition or the integrity of a single object or entity in order to make a decision about granting access to restricted resources or functionality.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-16 · CAPEC-274 · CAPEC-49 · CAPEC-55 · CAPEC-560 · CAPEC-565 · CAPEC-600 · CAPEC-652 · CAPEC-653 · CAPEC-70

CVEs mapped to this weakness (1)

  • CVE-2024-24771HigFeb 7, 2024
    risk 0.50cvss 7.7epss 0.01

    Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who have their credentials (username + password) compromised could potentially have the…