CWE-301

Reflection Attack in an Authentication Protocol

High

Description

Simple authentication protocols are subject to reflection attacks if a malicious user can use the target machine to impersonate a trusted user.

Potential Impact

How to Fix

Architecture and Design

Use different keys for the initiator and responder or of a different type of challenge for the initiator and responder.

Architecture and Design

Let the initiator prove its identity before proceeding.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-301 vulnerabilities in your codebase.

Get Security Assessment