CWE-1302

Missing Source Identifier in Entity Transactions on a System-On-Chip (SOC)

Medium

Description

The product implements a security identifier mechanism to differentiate what actions are allowed or disallowed when a transaction originates from an entity. A transaction is sent without a security identifier.

Potential Impact

How to Fix

Architecture and Design

Transaction details must be reviewed for design inconsistency and common weaknesses.

Implementation

Security identifier definition and programming flow must be tested in pre-silicon and post-silicon testing.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-1302 vulnerabilities in your codebase.

Get Security Assessment