CWE-1273

Device Unlock Credential Sharing

Medium

Description

The credentials necessary for unlocking a device are shared across multiple parties and may expose sensitive information.

Potential Impact

How to Fix

Integration

Ensure the unlock credentials are shared with the minimum number of parties and with utmost secrecy. To limit the risk associated with compromised credentials, where possible, the credentials should be part-specific.

Manufacturing

Ensure the unlock credentials are shared with the minimum number of parties and with utmost secrecy. To limit the risk associated with compromised credentials, where possible, the credentials should be part-specific.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-1273 vulnerabilities in your codebase.

Get Security Assessment