CWE-1293

Missing Source Correlation of Multiple Independent Data

Medium

Description

The product relies on one source of data, preventing the ability to detect if an adversary has compromised a data source.

Potential Impact

How to Fix

Requirements

Design system to use a Practical Byzantine fault method, to request information from multiple sources to verify the data and report on potentially compromised information sources.

Implementation

Failure to use a Practical Byzantine fault method when requesting data. Lack of place to report potentially compromised information sources. Relying on non-independent information sources for integrity checking. Failure to report information sources that respond in the minority to incident response procedures.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-1293 vulnerabilities in your codebase.

Get Security Assessment