COMMON WEAKNESS ENUMERATIONDraft
CWE-306
Missing Authentication for Critical Function
Abstraction
Base
Structure
Simple
Likelihood of Exploit
High
Understand the problem
What is the problem?
Root cause
How and when does the problem arise?
Lifecycle phase
Architecture and Design
Lifecycle phase
Architecture and Design
Lifecycle phase
Operation
Risk
What does successful exploitation lead to?
Gain Privileges or Assume IdentityVaries by Context
Defence
How is it prevented and fixed?
Architecture and Design
Architecture and design approach
Detail
Architecture and Design
Architecture and design approach
Architecture and Design
Architecture and design approach
Detail
Architecture and Design
Architecture and design approach
Architecture and Design
Architecture and design approach
Detail
Architecture and Design
Architecture and design approach
Architecture and Design
Libraries or Frameworks
Detail
Architecture and Design
Libraries or Frameworks
Implementation · System Configuration · Operation
Defence to apply across several lifecycle phases
Detail
Implementation · System Configuration · Operation
Defence to apply across several lifecycle phases
Verification
How is it detected?
Manual Analysis
Automated Static Analysis
LimitedManual Static Analysis - Binary or Bytecode
SOAR PartialDynamic Analysis with Automated Results Interpretation
SOAR PartialDynamic Analysis with Manual Results Interpretation
SOAR PartialManual Static Analysis - Source Code
SOAR PartialAutomated Static Analysis - Source Code
SOAR PartialArchitecture or Design Review
HighMITRE diagram
Weakness relationships and flow
