COMMON WEAKNESS ENUMERATIONDraft
CWE-276
Incorrect Default Permissions
Abstraction
Base
Structure
Simple
Likelihood of Exploit
Medium
Understand the problem
What is the problem?
Root cause
How and when does the problem arise?
Lifecycle phase
Architecture and Design
Lifecycle phase
Implementation
Lifecycle phase
Installation
Lifecycle phase
Operation
Risk
What does successful exploitation lead to?
Read Application DataModify Application Data
Defence
How is it prevented and fixed?
Architecture and Design · Operation
Defence to apply across several lifecycle phases
Detail
Architecture and Design · Operation
Defence to apply across several lifecycle phases
Architecture and Design
Separation of Privilege
Detail
Architecture and Design
Separation of Privilege
Verification
How is it detected?
Automated Static Analysis - Binary or Bytecode
SOAR PartialManual Static Analysis - Binary or Bytecode
SOAR PartialDynamic Analysis with Automated Results Interpretation
SOAR PartialDynamic Analysis with Manual Results Interpretation
HighManual Static Analysis - Source Code
HighAutomated Static Analysis - Source Code
SOAR PartialAutomated Static Analysis
SOAR PartialArchitecture or Design Review
HighMITRE diagram
Weakness relationships and flow
