COMMON WEAKNESS ENUMERATIONDraft

CWE-345

Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Abstraction

Class

Structure

Simple

Likelihood of Exploit

Medium

Understand the problem

What is the problem?

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Root cause

How and when does the problem arise?

Lifecycle phase

Architecture and Design

Lifecycle phase

Implementation

REALIZATION: This weakness is caused during implementation of an architectural security tactic.

Risk

What does successful exploitation lead to?

Varies by ContextUnexpected State

Affected security scopes: Integrity, Other

Defence

How is it prevented and fixed?

  • Follow secure coding guidelines for input handling and boundary checking.
  • Enforce strict security reviews and automated static analysis (SAST) checks.

Verification

How is it detected?

Automated Static Analysis

High
Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)