CWE-1268

Policy Privileges are not Assigned Consistently Between Control and Data Agents

Medium

Description

The product's hardware-enforced access control for a particular resource improperly accounts for privilege discrepancies between control and write policies.

Potential Impact

How to Fix

Architecture and Design

Access-control-policy definition and programming flow must be sufficiently tested in pre-silicon and post-silicon testing.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-1268 vulnerabilities in your codebase.

Get Security Assessment