CWE-636

Not Failing Securely ('Failing Open')

High

Description

When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Potential Impact

How to Fix

Architecture and Design

Subdivide and allocate resources and components so that a failure in one part does not affect the entire product.

Related Weaknesses

References

View on MITRE CWE Database →

Need Help Fixing This Vulnerability?

Our security experts can help you identify and remediate CWE-636 vulnerabilities in your codebase.

Get Security Assessment