The product's hardware-enforced access control for a particular resource improperly accounts for privilege discrepancies between control and write policies.
Access-control-policy definition and programming flow must be sufficiently tested in pre-silicon and post-silicon testing.
Our security experts can help you identify and remediate CWE-1268 vulnerabilities in your codebase.
Get Security Assessment