When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.
Subdivide and allocate resources and components so that a failure in one part does not affect the entire product.
Our security experts can help you identify and remediate CWE-636 vulnerabilities in your codebase.
Get Security Assessment